CVE-2024-52964

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9

Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.006
48.9th percentile
Discovered by
Third party
Vendor advisory field
Published
Aug 12, 2025
Assigned by fortinet

Description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiManager

Credit

External

Vendor remediation

Please upgrade to FortiManager Cloud version 7.6.2 or above Please upgrade to FortiManager Cloud version 7.4.6 or above Please upgrade to FortiManager Cloud version 7.2.10 or above Please upgrade to FortiManager version 7.6.2 or above Please upgrade to FortiManager version 7.4.7 or above Please upgrade to FortiManager version 7.4.6 or above Please upgrade to FortiManager version 7.2.10 or above Please upgrade to FortiManager version 7.0.14 or above

Something wrong here?