Description | Versions prior to R1 2020 (2020.1.114) are susceptible to remote code execution attacks on affected web servers of Telerik User Interface (UI) for ASP-NET due to a deserialization vulnerability found in RadAsyncUpload function. FortiGuard Labs continue seeing high exploitation activity of these old vulnerabilities. |
CVEs | CVE-2019-18935, CVE-2017-11317, CVE-2017-11357 |
Severity | High |
Posted on | Mar 09, 2023 |
Outbreak Report Link | https://www.fortiguard.com/outbreak-alert/progress-telerik-ui-attack |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.