The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortios | Fortinet | * | 2.8_mr10 (including) |
Fortios | Fortinet | * | 3_beta (including) |