Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1. through 5.1.2 may allow an authenticated attacker to read and delete arbitrary file of the system via crafted HTTP or HTTPs requests.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Fortinet FortiWAN 安全漏洞
Vulnerability Description
Fortinet FortiWAN是美国飞塔(Fortinet)公司的一个网络设备。用于在不同网络之间执行负载平衡和容错。 Fortinet FortiWAN 5.2.0 至 5.2.1、5.1.1 至 5.1.2版本存在安全漏洞,该漏洞源于对受限制目录的路径名限制不当,允许经过身份验证的攻击者通过构建的 HTTP 读取和删除系统的任意文件,或者HTTPs 请求。
CVSS Information
N/A
Vulnerability Type
N/A