The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
Score CVSS v2.0
10.0
/ 10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
Informations
- Publié
- 31 déc. 2005
- Mis à jour
- 16 avr. 2026
- Statut
- Modified
- Source
- cve@mitre.org
Produits affectés
fortinet fortiosToutes les CVE Fortinet FortiOS →
Versions : 2.8_mr10, 3_beta
fortinet fortigate
Versions : 2.8
Faiblesses (CWE)
NVD-CWE-noinfo
Références (12)
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
Surveillez vos produits
Recevez une alerte automatique à chaque nouvelle CVE affectant vos équipements.