CVE-2024-52964
published 2025-08-12CVE-2024-52964: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1…
PriorityP343medium6.5CVSS 3.1
AVNACLPRHUINSUCNIHAH
EPSS
0.60%
44.8th percentile
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.2.0 < 7.0.14 | 7.0.14 |
| fortinet | fortimanager | 6.2.0 – 6.2.13 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.13 | — |
| fortinet | fortimanager | >= 7.2.0 < 7.2.10 | 7.2.10 |
| fortinet | fortimanager | 7.2.0 – 7.2.9 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.6 | 7.4.6 |
| fortinet | fortimanager | 7.4.0 – 7.4.5 | — |
| fortinet | fortimanager | >= 7.6.0 < 7.6.2 | 7.6.2 |
| fortinet | fortimanager | 7.6.0 – 7.6.1 | — |
| fortinet | fortimanager_cloud | 6.4.1 – 7.0.13 | — |
| fortinet | fortimanager_cloud | >= 7.2.1 < 7.2.10 | 7.2.10 |
| fortinet | fortimanager_cloud | >= 7.4.1 < 7.4.6 | 7.4.6 |
| fortinet | fortimanagercloud | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-535p-g7m4-r8xm: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7
ghsa_unreviewed·2025-08-12
CVE-2024-52964 [MEDIUM] CWE-22 GHSA-535p-g7m4-r8xm: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.
Fortinet
Arbitrary file overwrite in FGFMd
vendor_fortinet·2025-08-12·CVSS 5.5
CVE-2024-52964 [MEDIUM] CWE-22 Arbitrary file overwrite in FGFMd
FG-IR-24-473: Arbitrary file overwrite in FGFMd
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.
CVEs: CVE-2024-52964
CWEs: CWE-22
CVSS: 5.5 (medium)
Affected products: FortiManager, FortiManagercloud, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-12
Published