← Back

CVE-2024-36508

nvd nist
Published: Feb 11, 2025Modified: Jul 24, 2025

JSON object

Loading...
6.0
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Exploitability: 0.8 / Impact: 5.2
Source: psirt@fortinet.com (Secondary)

Description

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.

Affected (4)

2 products
Fortimanager
Fortianalyzer
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 7.2.6
From 7.4.0 to 7.4.3
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 7.2.6
From 7.4.0 to 7.4.3

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.