跳转到帖子

Fortinet FortiManager: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2024-32116)

recommended_posts

发布于
  • Members

Fortinet FortiManager: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2024-32116)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
11/12/2024
Created
02/05/2025
Added
02/02/2025
Modified
02/05/2025

Description

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.

Solution(s)

  • fortinet-fortimanager-upgrade-7_2_6
  • fortinet-fortimanager-upgrade-7_4_3

References

  • https://attackerkb.com/topics/cve-2024-32116
  • CVE - 2024-32116
  • https://fortiguard.fortinet.com/psirt/FG-IR-24-099
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…