A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, 7.2.0 through 7.2.11, 7.0.0 through 7.0.18, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiManager Cloud versions 7.4.1 through 7.4.3 may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-259 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-01-14 14:15
Updated : 2025-08-08 16:00
NVD link : CVE-2024-48884
Mitre link : CVE-2024-48884
CVE.ORG link : CVE-2024-48884
JSON object : View
Products Affected
fortinet
- fortiweb
- fortios
- fortivoice
- fortirecorder
- fortimanager
- fortiproxy
- fortimanager_cloud
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
