FG-IR-26-122: Path Traversal in CLI
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] in the command line interpreter of FortiOS, FortiPAM, FortiProxy and FortiSwitchManager may allow a privileged attacker to achieve arbitrary write or delete files via specifically crafted arguments to existing commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-122?
FG-IR-26-122 has a high severity rating due to its potential for allowing arbitrary write or deletion of files.
How do I fix FG-IR-26-122?
To remediate FG-IR-26-122, update affected installations of FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager to their latest recommended versions.
Which products are affected by FG-IR-26-122?
FG-IR-26-122 affects FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager versions as specified in the advisory.
What kind of attack does FG-IR-26-122 enable?
FG-IR-26-122 enables a privileged attacker to perform path traversal attacks that can lead to unauthorized file access.
Is FG-IR-26-122 easy to exploit?
Exploitation of FG-IR-26-122 typically requires some level of user privilege, but the path traversal vulnerability makes it easier for attackers to execute arbitrary commands.