FG-IR-26-151: Path traversal in CLI command allows deletion of root file system
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-151?
The severity of FG-IR-26-151 is classified as medium with a score of 5.
How do I fix FG-IR-26-151?
To fix FG-IR-26-151, ensure that your Fortinet devices are updated with the latest firmware that addresses this vulnerability.
What systems are affected by FG-IR-26-151?
FG-IR-26-151 affects FortiOS, FortiPAM, FortiProxy, and FortiSwitch Manager.
What type of attacker can exploit FG-IR-26-151?
A privileged authenticated attacker with physical access to the device can exploit FG-IR-26-151.
What is the potential impact of FG-IR-26-151?
The potential impact of FG-IR-26-151 is the deletion of the file system on the affected Fortinet devices.