CVE-2024-32117

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4

Severity
Medium 4.7
CVSS 3.1
Exploited
Not listed
EPSS
0.009
56.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Nov 12, 2024
Assigned by fortinet

Description

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiManager
  • Fortinet · FortiAnalyzer

Credit

Internallly discovered and reported by Théo Leleu of Fortinet product security team.

Vendor remediation

Please upgrade to FortiManager version 7.4.3 or above Please upgrade to FortiManager version 7.2.6 or above Please upgrade to FortiAnalyzer version 7.4.3 or above Please upgrade to FortiAnalyzer version 7.2.6 or above Please upgrade to FortiAnalyzer-BigData version 7.4.1 or above Please upgrade to FortiAnalyzer-BigData version 7.2.8 or above

Something wrong here?