9.1

CVE-2024-48884

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, 7.2.0 through 7.2.11, 7.0.0 through 7.0.18, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiManager Cloud versions 7.4.1 through 7.4.3 may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder

Data is provided by the National Vulnerability Database (NVD)
FortinetFortimanager Version >= 7.4.1 < 7.4.4
FortinetFortimanager Version >= 7.6.0 < 7.6.2
FortinetFortimanager Cloud Version >= 7.4.1 < 7.4.4
FortinetFortiproxy Version >= 1.0.0 < 7.0.19
FortinetFortiproxy Version >= 7.2.0 < 7.2.12
FortinetFortiproxy Version >= 7.4.0 < 7.4.6
FortinetFortirecorder Version >= 7.0.0 < 7.0.5
FortinetFortirecorder Version >= 7.2.0 < 7.2.2
FortinetFortivoice Version >= 6.0.0 <= 6.4.10
FortinetFortivoice Version >= 7.0.0 <= 7.0.5
FortinetFortiweb Version >= 6.4.0 < 7.4.5
FortinetFortiweb Version7.6.0
FortinetFortios Version >= 6.4.0 < 6.4.16
FortinetFortios Version >= 7.0.0 < 7.0.16
FortinetFortios Version >= 7.2.0 < 7.2.10
FortinetFortios Version >= 7.4.0 < 7.4.5
FortinetFortios Version7.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.54% 0.666
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
psirt@fortinet.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.