CVE-2024-40588
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.8 / Impact: 3.6
Source: psirt@fortinet.com (Secondary)
Description
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.6, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiRecorder 6.4 all versions, FortiVoice 7.0.0 through 7.0.3, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.
Affected (9)
Products: Fortinet: Forticamera Firmware, Fortimail, Fortindr, Fortirecorder, Fortivoice
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.1.4 |
| Running on/with | Platform Versions |
|---|---|
Fortinet Forticamera | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.4.0 to 7.0.5 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.0.0 to 6.4.10 |
References (1)
Timeline
No history available yet.