Attackers are exploiting an unauthenticated FortiMail path before the effective fix ships.
The public management interface yields arbitrary file write and command execution.
Fortinet FortiMail, a physical, virtual or cloud-deployed secure email gateway appliance.
Unauthenticated arbitrary file write and command execution on a FortiMail appliance
Observed exploitation and the absence of a shipped effective fix turn exposed management interfaces into an immediate containment problem.
Detail and 4 sources
An unauthenticated caller can reach the path through an affected FortiMail HTTP or HTTPS management interface.
Path traversal and NULL-byte handling let that caller write attacker-chosen files to the appliance filesystem.
The written file can then be used to execute unauthorized commands in the FortiMail system context.
Exploitation is occurring while the effective correction remains announced rather than shipped, and pre-fix images remain accepted.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
The fixed builds were still described as upcoming, so no fixed image, release notes, or patch diff was available for direct inspection.