CVE-2024-47566
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete
Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.002
9.6th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiRecorder | Other Products | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiRecorder
Credit
Internally discovered and reported by Théo Leleu of Fortinet Product Security team.
Vendor remediation
Please upgrade to FortiRecorder version 7.2.2 or above Please upgrade to FortiRecorder version 7.0.5 or above