The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
CVSS v2.0 Score
10.0
/ 10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
Information
- Published
- 31 déc. 2005
- Updated
- 16 avr. 2026
- Status
- Modified
- Source
- cve@mitre.org
Affected products
fortinet fortiosAll Fortinet FortiOS CVEs →
Versions : 2.8_mr10, 3_beta
fortinet fortigate
Versions : 2.8
Weaknesses (CWE)
NVD-CWE-noinfo
References (12)
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.