Path traversal in FortiMail - CVE-2021-24013

 

Path traversal in FortiMail - CVE-2021-24013

Published: July 13, 2021


Vulnerability identifier: #VU54731
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-24013
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user  can send a specially crafted HTTP request and read arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

FortiMail

How to mitigate CVE-2021-24013

Install update from vendor's website.

FortiMail - addressed in versions 6.0.11, 6.2.7, 6.4.4

External References

Related Security Bulletins