ID:10923 - Exploit for Path traversal in FortiOS - CVE-2018-13379
Published: November 29, 2024
FortiOS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote non-authenticated attacker can send a specially crafted HTTP request and download arbitrary file from FortiOS SSL VPN web portal.
Remediation
Install updates from vendor's website.
As a temporary solution, disable the SSL-VPN web portal service by applying the following CLI commands:
config vpn ssl settings
unset source-interface
end