Fortinet FortiWeb directory traversal | CVE-2021-42753
NAME
Fortinet FortiWeb directory traversal
- Platforms Affected:
Fortinet Fortiweb 5.0.3
Fortinet Fortiweb 4.4.7
Fortinet Fortiweb 5.1
Fortinet Fortiweb 5.0
Fortinet Fortiweb 5.2.0
Fortinet Fortiweb 5.2.1
Fortinet Fortiweb 5.3.4
Fortinet Fortiweb 5.2
Fortinet Fortiweb 5.1.2
Fortinet Fortiweb 5.5.2
Fortinet Fortiweb 4.4.6
Fortinet FortiWeb 5.7.1
Fortinet FortiWeb 5.8.2
Fortinet FortiWeb 5.8.0
Fortinet FortiWeb 5.6.0
Fortinet FortiWeb 6.0.2
Fortinet FortiWeb 6.2.0
Fortinet FortiWeb 6.3.0
Fortinet FortiWeb 6.3.7
Fortinet FortiWeb 6.2.3
Fortinet FortiWeb 6.3.8
Fortinet FortiWeb 6.2.4
Fortinet FortiWeb 6.3.4
Fortinet FortiWeb 6.3.13
Fortinet FortiWeb 6.3.14
Fortinet FortiWeb 6.2.4
Fortinet FortiWeb 6.2.5
Fortinet FortiWeb 6.3.15
Fortinet FortiWeb 6.4.0
Fortinet FortiWeb 6.3.15
Fortinet FortiWeb 6.4.1
Fortinet FortiWeb 6.0
Fortinet FortiWeb 6.1
Fortinet FortiWeb 5.9
Fortinet FortiWeb 6.1.2
Fortinet FortiWeb 6.2.6
Fortinet FortiWeb 6.0.7
Fortinet FortiWeb 6.3.16
Fortinet FortiWeb 6.3.11 - Risk Level:
8.1 - Exploitability:
Unproven - Consequences:
Obtain Information
DESCRIPTION
Fortinet FortiWeb could allow a remote authenticated attacker to traverse directories on the system, caused by improper validation of user requests. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) in the device filesystem to delete arbitrary files on the system.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Refer to FortiGuard Advisory FG-IR-21-158 for patch, upgrade or suggested workaround information. See References.
- Reference Link:
https://www.fortiguard.com/psirt/FG-IR-21-158 - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42753
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.