Nov. 14, 2023, 8 a.m. |

FortiGuard Labs | FortiGuard Center - IR Advisories fortiguard.fortinet.com

*PRODUCT OUT OF SUPPORT*
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiWAN may allow an authenticated attacker to read and delete arbitrary file of the system via crafted HTTP or HTTPs requests.

attacker cwe delete directory file http https may path path traversal product requests restricted support system vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Anti-fraud and Compliance Support Agent (Armenia)

@ Manychat | Yerevan, Armenia

ATC Instructor - Cybersecurity

@ Fulton County Schools | Atlanta, GA, US, 30339

Senior Cyber Threat Intel Analyst

@ Maveris | Washington, District of Columbia, United States - Remote

Head of Information Security

@ Catawiki | The Hague, Netherlands

Security Architect

@ Ocorian | London, United Kingdom