A path traversal vulnerability in the FortiOS SSL VPN web portal may allow attackers to gain unauthorized access to system files. This is done through specially crafted HTTP resource requests. The vulnerability as been classified as CVE-2018-13379.
The affected products are:
Any versions above the ones listed are unaffected. The vulnerability is only possible while the SSL VPN service (web-mode or tunnel mode) is enabled.
Solutions and workarounds:
The solutions to this problem are:
For more information on this vulnerability, please visit the following URL:
The Guyana National CIRT recommends that users and administrators review this alert and the remediation strategies and apply them where necessary.
References