Fortinet FortiOS version 7.2.0부터 7.2.1까지 및 version 7.0.0부터 7.0.6까지, FortiProxy version 7.2.0 및 version 7.0.0부터 7.0.6까지, FortiSwitchManager version 7.2.0 및 7.0.0에서 대체 경로나 채널을 사용하는 인증 우회[cwe-288]로 인해 인증되지 않은 공격자가 특수하게 조작된 HTTP 또는 HTTPS 요청을 통해 관리 인터페이스에서 작업을 수행할 수 있습니다.
Fortinet FortiOS version 7.2.0부터 7.2.1까지 및 version 7.0.0부터 7.0.6까지, FortiProxy version 7.2.0 및 version 7.0.0부터 7.0.6까지, FortiSwitchManager version 7.2.0 및 7.0.0에서 대체 경로나 채널을 사용하는 인증 우회[cwe-288]로 인해 인증되지 않은 공격자가 특수하게 조작된 HTTP 또는 HTTPS 요청을 통해 관리 인터페이스에서 작업을 수행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
영향 제품·버전
제품 Fortinet FortiOS, FortiProxy, FortiSwitchManager