CVE-2024-46664
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or
Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.005
41.3th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet
Description
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiRecorder | Other Products | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiRecorder
Vendor remediation
Please upgrade to FortiRecorder version 7.2.2 or above Please upgrade to FortiRecorder version 7.0.5 or above