CVE-2024-48892
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a
Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.004
34.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Aug 12, 2025
Assigned by fortinet
Description
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSOAR
Credit
Fortinet is pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiSOAR version 7.6.1 or above Please upgrade to FortiSOAR version 7.5.2 or above