CVE-2024-36508
published 2025-02-11CVE-2024-36508: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2…
PriorityP428medium6CVSS 3.1
AVLACLPRHUINSUCNIHAH
EPSS
0.23%
14.2th percentile
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortianalyzer | 6.4.0 – 6.4.15 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.13 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.5 | — |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortianalyzer | 7.4.0 – 7.4.2 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.13 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.5 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Multiple arbitrary file deletion in the CLI
vendor_fortinet·2025-02-11·CVSS 6.0
CVE-2024-36508 [MEDIUM] CWE-22 Multiple arbitrary file deletion in the CLI
FG-IR-24-147: Multiple arbitrary file deletion in the CLI
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
CVEs: CVE-2024-36508
CWEs: CWE-22
CVSS: 6.0 (medium)
Affected products: FortiAnalyzer, FortiManager, Fortinet
GHSA
GHSA-7w3h-vqp8-323r: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7
ghsa_unreviewed·2025-02-11
CVE-2024-36508 [MEDIUM] CWE-22 GHSA-7w3h-vqp8-323r: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-11
Published