CVE-2024-36508
6.0
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Exploitability: 0.8 / Impact: 5.2
Source: psirt@fortinet.com (Secondary)
Description
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
Affected (4)
Products: Fortinet: Fortimanager, Fortianalyzer
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.4.0 to 7.2.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.4.0 to 7.2.6 |
References (1)
Timeline
No history available yet.