CVE-2024-36508Path Traversal in Fortinet Fortianalyzer

CWE-22Path Traversal4 documents4 sources
Severity
6.0MEDIUMNVD
EPSS
0.1%
top 76.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11

Description

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 0.8 | Impact: 5.2

Affected Packages4 packages

NVDfortinet/fortimanager6.4.07.2.6+1
NVDfortinet/fortianalyzer6.4.07.2.6+1
CVEListV5fortinet/fortimanager7.4.07.4.2+3
CVEListV5fortinet/fortianalyzer7.4.07.4.2+3

🔴Vulnerability Details

2
GHSA
GHSA-7w3h-vqp8-323r: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 72025-02-11
CVEList
CVE-2024-36508: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 72025-02-11

📋Vendor Advisories

1
Fortinet
Multiple arbitrary file deletion in the CLI2025-02-11
CVE-2024-36508 — Path Traversal in Fortinet | cvebase