#VU18609 Path traversal in FortiOS - CVE-2018-13379
Published: May 27, 2019 / Updated: November 29, 2024
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote non-authenticated attacker can send a specially crafted HTTP request and download arbitrary file from FortiOS SSL VPN web portal.
Remediation
Install updates from vendor's website.
As a temporary solution, disable the SSL-VPN web portal service by applying the following CLI commands:
config vpn ssl settings
unset source-interface
end