vendor:
FortiWeb
by:
BINAR10
8,5
CVSS
HIGH
Policy Bypass
20
CWE
Product Name: FortiWeb
Affected Version From: Latest update to Tue, 2 May 2012
Affected Version To: Latest update to Tue, 2 May 2012
Patch Exists: Yes
Related CWE: CVE-2012-1234
CPE: a:fortinet:fortiweb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
BINAR10 Report on Fortinet Fortiweb Findings 02/05/2012 – Fortinet FortiWeb Web Application Firewall Policy Bypass –
When is appended to a POST request any padding data that surpasses 2399 bytes, the WAF do not inspect the data sent and the request hits directly the application. This should occur when the product is not configured to block malformed requests, but this feature also check the POST size limit, blocking the request if it surpass a fixed limit, therefore is likely that is being disabled due to application requirements in medium size forms. The same issue with POST Request but it could be done through the sending arbitrary data at the end of the URL.
Mitigation:
The mitigation for this vulnerability is to configure the WAF to block malformed requests and to set a limit for the POST and GET requests.