The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortios | - | 2.8_mr10.x |
| fortinet / fortios | - | 3_beta.x |
| fortinet / fortigate | 2.8 | 2.8.x |