CVE-2024-46664

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or

Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.005
41.3th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet

Description

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.

Weakness: CWE-23

Affected products

Vendor Product Category Matched by
Fortinet FortiRecorder Other Products cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiRecorder

Vendor remediation

Please upgrade to FortiRecorder version 7.2.2 or above Please upgrade to FortiRecorder version 7.0.5 or above