Path Traversal Vulnerability in Fortinet FortiWAN Product
CVE-2023-44251
8.1HIGH
Summary
A path traversal vulnerability in Fortinet's FortiWAN allows an authenticated attacker to manipulate file paths in HTTP/HTTPS requests. This could enable unauthorized access to sensitive files or allow for their deletion. The issue affects specific versions of FortiWAN, highlighting the need for users to patch their installations and conduct thorough security audits.
Affected Version(s)
FortiWAN 5.2.0 <= 5.2.1
FortiWAN 5.1.1 <= 5.1.2
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved