CVE-2024-46664
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or
Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.005
43.8th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiRecorder | Other Products | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiRecorder
Credit
Internally discovered and reported by Théo Leleu of Fortinet Product Security team.
Vendor remediation
Please upgrade to FortiRecorder version 7.2.2 or above Please upgrade to FortiRecorder version 7.0.5 or above