← All CVEs

CVE-2024-48884

high · 7.5

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder

7.5
CVSS
15.3%
EPSS (exploit prob.)
97th
EPSS percentile
2025-01-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
fortinetfortimanager>= 7.4.1, < 7.4.4
fortinetfortimanager>= 7.6.0, < 7.6.2
fortinetfortimanager_cloud>= 7.4.1, < 7.4.4
fortinetfortiproxy>= 1.0.0, < 7.0.19
fortinetfortiproxy>= 7.2.0, < 7.2.12
fortinetfortiproxy>= 7.4.0, < 7.4.6
fortinetfortirecorder>= 7.0.0, < 7.0.5
fortinetfortirecorder>= 7.2.0, < 7.2.2
fortinetfortivoice>= 6.0.0, <= 6.4.10
fortinetfortivoice>= 7.0.0, <= 7.0.5
fortinetfortiweb>= 6.4.0, < 7.4.5
fortinetfortiweb7.6.0
fortinetfortios>= 6.4.0, < 6.4.16
fortinetfortios>= 7.0.0, < 7.0.16
fortinetfortios>= 7.2.0, < 7.2.10
fortinetfortios>= 7.4.0, < 7.4.5
fortinetfortios7.6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-48884