FG-IR-20-233: [FortiProxy] file leaking through SSL VPN language resource request
A path traversal vulnerability in the FortiProxy SSL VPN web portal may allow a non-authenticated, remote attacker to download FortiProxy system files through specially crafted HTTP resource requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-20-233?
The severity of FG-IR-20-233 is critical due to the potential for remote attackers to exploit the vulnerability and download sensitive system files.
How do I fix FG-IR-20-233?
To fix FG-IR-20-233, update the FortiProxy software to the latest version provided by Fortinet.
Can FG-IR-20-233 be exploited without authentication?
Yes, FG-IR-20-233 can be exploited by non-authenticated users, making it more dangerous.
What types of systems are affected by FG-IR-20-233?
FG-IR-20-233 affects systems running Fortinet FortiProxy.
How can I determine if my system is vulnerable to FG-IR-20-233?
You can determine if your system is vulnerable to FG-IR-20-233 by checking for the affected FortiProxy version and reviewing any security advisories from Fortinet.