Path Traversal Vulnerability in Fortinet FortiManager
CVE-2024-32115

5.2MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
14 January 2025

Summary

A relative path traversal vulnerability in Fortinet FortiManager allows a privileged attacker to craft malicious HTTP or HTTPS requests that can lead to unauthorized file deletions from the system's underlying filesystem. This vulnerability affects multiple versions of FortiManager, allowing potential exploitation by users with malicious intent to disrupt services and compromise sensitive data.

Affected Version(s)

FortiManager 7.4.0 <= 7.4.2

FortiManager 7.2.0 <= 7.2.5

FortiManager 7.0.0 <= 7.0.13

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.