CVE-2025-22859

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arb

Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.006
46.4th percentile
Discovered by
Third party
Vendor advisory field
Published
May 13, 2025
Assigned by fortinet

Description

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

Weakness: CWE-23

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientEMS

Credit

Fortinet is pleased to thank Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiClientEMS Cloud version 7.4.3 or above Please upgrade to FortiClientEMS version 7.4.3 or above

Something wrong here?