CVE-2024-48884
published 2025-01-14CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1…
PriorityP273critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
14.94%
96.3th percentile
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortimanager | 7.4.1 – 7.4.3 | — |
| fortinet | fortimanager | >= 7.6.0 < 7.6.2 | 7.6.2 |
| fortinet | fortimanager | 7.6.0 – 7.6.1 | — |
| fortinet | fortimanager_cloud | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortimanager_cloud | 7.4.1 – 7.4.3 | — |
| fortinet | fortimanagercloud | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 6.4.16 | 6.4.16 |
| fortinet | fortios | 6.4.0 – 6.4.15 | — |
| fortinet | fortios | >= 7.0.0 < 7.0.16 | 7.0.16 |
| fortinet | fortios | 7.0.0 – 7.0.15 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.10 | 7.2.10 |
| fortinet | fortios | 7.2.0 – 7.2.9 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | fortios | 7.4.0 – 7.4.4 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 1.0.0 < 7.0.19 | 7.0.19 |
| fortinet | fortiproxy | 1.0.0 – 1.0.7 | — |
| fortinet | fortiproxy | 1.1.0 – 1.1.6 | — |
| fortinet | fortiproxy | 1.2.0 – 1.2.13 | — |
| fortinet | fortiproxy | 2.0.0 – 2.0.14 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability resides in the csfd daemon; monitor for anomalous activity or crashes in the csfd process on affected Fortinet products ↗
- →Unauthenticated attackers can delete arbitrary folders via path traversal; monitor for unexpected directory deletions on the security fabric interface ↗
- →Authenticated attackers with access to the security fabric interface and port can write arbitrary files; monitor for unexpected file creation outside expected directories on FortiManager, FortiOS, and FortiProxy ↗
- →For CVE-2024-48885, path traversal via specially crafted packets can lead to privilege escalation on FortiRecorder, FortiVoice, and FortiWeb; inspect inbound packets for path traversal sequences (e.g., ../) targeting these products ↗
- ·Exploitation of the write-arbitrary-files vector requires the attacker to be authenticated AND have access to the security fabric interface and port; restrict access to this interface as a mitigation ↗
- ·The unauthenticated folder-deletion vector does not require credentials, making it higher risk for internet-exposed security fabric interfaces ↗
- ·FortiProxy 1.0, 1.1, 1.2, and 2.0 ALL versions are affected with no patched release indicated in the advisory; plan migration or compensating controls accordingly ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qhwf-jg9m-cq9f: A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7
ghsa_unreviewed·2025-01-14
CVE-2024-48884 [HIGH] CWE-22 GHSA-qhwf-jg9m-cq9f: A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, 7.2.0 through 7.2.11, 7.0.0 through 7.0.18, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiVoice versions 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.0 through 6.0.12, FortiWeb 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, 6.4.0 through 6.4.3 allows attacker to trigger an escalation of privilege via specially craf
CISA ICS
Siemens RUGGEDCOM APE1808 Devices
cisa_ics·2025-02-13·CVSS 6.5
[MEDIUM] Siemens RUGGEDCOM APE1808 Devices
ICS Advisory
##
Siemens RUGGEDCOM APE1808 Devices
Release DateFebruary 13, 2025
Alert CodeICSA-25-044-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808 Devices
- Vulnerabilities: Out-of-bounds Read, Insertion of Sensitive Information Into Sent Data, Allocat
Fortinet
Path traversal in csfd daemon
vendor_fortinet·2025-01-14·CVSS 7.5
CVE-2024-48884 [HIGH] CWE-22 Path traversal in csfd daemon
FG-IR-24-259: Path traversal in csfd daemon
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder
A imp
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published