FortiOS / FortiProxy - Path traversal vulnerability allows VDOM escaping

Summary

A relative path traversal vulnerability [CWE-23] in FortiOS and FortiProxy may allow privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.

Version Affected Solution
FortiOS 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiOS 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiOS 6.4 6.4.0 through 6.4.11 Upgrade to 6.4.12 or above
FortiOS 6.2 6.2.0 through 6.2.12 Upgrade to 6.2.13 or above
FortiProxy 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiProxy 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above
FortiProxy 2.0 2.0.0 through 2.0.11 Upgrade to 2.0.12 or above
FortiProxy 1.2 1.2 all versions Migrate to a fixed release
FortiProxy 1.1 1.1 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Note: Impact on FortiProxy 7.0.x, 2.0.x, 1.2.x, 1.1.x is minor as it does not have VDOMs

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2023-03-07: Initial publication