CVE-2023-41682: Path Traversal
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 2.5.0 through 2.5.2 and 2.4.1 and 2.4.0 allows attacker to denial of service via crafted http requests.
Other sources
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all versions allows attacker to denial of service via crafted http requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41682?
CVE-2023-41682 is a vulnerability in Fortinet FortiSandbox that allows an attacker to perform path traversal and cause denial of service through crafted HTTP requests.
Which versions of Fortinet FortiSandbox are affected by CVE-2023-41682?
Fortinet FortiSandbox versions 4.4.0, 4.2.0 through 4.2.5, 4.0.0 through 4.0.3, 3.2.0 through 3.2.4, 2.5.0 through 2.5.2, and 2.4.0 through 2.4.1 are affected by CVE-2023-41682.
How severe is CVE-2023-41682?
CVE-2023-41682 has a severity score of 7.5 (High).
How can an attacker exploit CVE-2023-41682?
An attacker can exploit CVE-2023-41682 by sending crafted HTTP requests that traverse restricted directories, leading to denial of service.
Is there a fix for CVE-2023-41682?
Yes, Fortinet has released patches to address the vulnerability. Please refer to the FortiGuard Advisory FG-IR-23-280 for more information.