FortiADC - Improper input validation in download features
Summary
Multiple improper input validation vulnerabilities [CWE-20] may allow an authenticated attacker to retrieve files with specific extensions from the underlying Linux system via crafted HTTP requests.
Affected Products
FortiADC version 7.1.0
FortiADC version 7.0.0 through 7.0.2
FortiADC version 6.2.0 through 6.2.4
FortiADC version 6.1 all versions
FortiADC version 6.0 all versions
FortiADC version 5.4 all versions
FortiADC version 5.3 all versions
FortiADC version 5.2 all versions
FortiADC version 5.1 all versions
Solutions
Please upgrade to FortiADC version 7.1.1 or abovePlease upgrade to FortiADC version 7.0.3 or above
Please upgrade to FortiADC version 6.2.5 or above