FG-IR-24-250 / Can someone Explain?
hi at all,
so, fortinet got some CVE's, nevermind... Every CVE i check if its attackable to our environment, ok...
but the FG-IR-24-250 one, i dont understand the concept...
Can someone explain this to me?
How could the unauthenticated attacker access the gui, or more like, how am i vulnerable?
Could the attacker attack is, if he get access to a gui? Like if he can access the SSL VPN Portal, he can use this attack unauthenticated pordal?
or is it only possible if the attacker got access to the admin GUI?
Admin GUI isnt accessable from external, and all SSL VPN Portals the Web-mode is disabled, but as the Web-mode-Login-PAge is still accessable... so is this a way to attack?
maybe everything is lost in translation at my point, and other people understand this CVE, but the reseller and technical service provider didnt understand the attack-possibilities too...
Can someone help me to learn something?:(
