FG-IR-26-120: Path Traversal in CLI
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-120?
The severity of FG-IR-26-120 is considered critical due to the potential for a privileged attacker to delete files from the filesystem.
How do I fix FG-IR-26-120?
To mitigate FG-IR-26-120, upgrade to FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, or FortiManager Cloud versions 7.6.5 or 7.4.8, depending on the product.
What products are affected by FG-IR-26-120?
FG-IR-26-120 affects FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud versions prior to their respective patched versions.
Can FG-IR-26-120 lead to unauthorized access?
Yes, FG-IR-26-120 can allow a privileged attacker to perform unauthorized file deletion, potentially impacting the security of the system.
Is there any workaround for FG-IR-26-120?
There are no known workarounds for FG-IR-26-120; applying the latest updates is essential for remediation.