cbcvebase.
CVE-2024-48884
published 2025-01-14

CVE-2024-48884: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1…

PriorityP273critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
14.94%
96.3th percentile
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortimanager
fortinetfortimanager>= 7.4.1 < 7.4.47.4.4
fortinetfortimanager7.4.1 – 7.4.3
fortinetfortimanager>= 7.6.0 < 7.6.27.6.2
fortinetfortimanager7.6.0 – 7.6.1
fortinetfortimanager_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortimanager_cloud7.4.1 – 7.4.3
fortinetfortimanagercloud
fortinetfortinet
fortinetfortios
fortinetfortios
fortinetfortios>= 6.4.0 < 6.4.166.4.16
fortinetfortios6.4.0 – 6.4.15
fortinetfortios>= 7.0.0 < 7.0.167.0.16
fortinetfortios7.0.0 – 7.0.15
fortinetfortios>= 7.2.0 < 7.2.107.2.10
fortinetfortios7.2.0 – 7.2.9
fortinetfortios>= 7.4.0 < 7.4.57.4.5
fortinetfortios7.4.0 – 7.4.4
fortinetfortiproxy
fortinetfortiproxy>= 1.0.0 < 7.0.197.0.19
fortinetfortiproxy1.0.0 – 1.0.7
fortinetfortiproxy1.1.0 – 1.1.6
fortinetfortiproxy1.2.0 – 1.2.13
fortinetfortiproxy2.0.0 – 2.0.14

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in the csfd daemon; monitor for anomalous activity or crashes in the csfd process on affected Fortinet products
  • Unauthenticated attackers can delete arbitrary folders via path traversal; monitor for unexpected directory deletions on the security fabric interface
  • Authenticated attackers with access to the security fabric interface and port can write arbitrary files; monitor for unexpected file creation outside expected directories on FortiManager, FortiOS, and FortiProxy
  • For CVE-2024-48885, path traversal via specially crafted packets can lead to privilege escalation on FortiRecorder, FortiVoice, and FortiWeb; inspect inbound packets for path traversal sequences (e.g., ../) targeting these products
  • ·Exploitation of the write-arbitrary-files vector requires the attacker to be authenticated AND have access to the security fabric interface and port; restrict access to this interface as a mitigation
  • ·The unauthenticated folder-deletion vector does not require credentials, making it higher risk for internet-exposed security fabric interfaces
  • ·FortiProxy 1.0, 1.1, 1.2, and 2.0 ALL versions are affected with no patched release indicated in the advisory; plan migration or compensating controls accordingly
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.