Path Traversal Vulnerability in Fortinet FortiManager and FortiAnalyzer
CVE-2024-33502
7.2HIGH
What is CVE-2024-33502?
A flaw has been identified in Fortinet’s FortiManager and FortiAnalyzer products, allowing an improper limitation of a pathname to a restricted directory. This vulnerability enables attackers to potentially execute unauthorized code or commands by crafting malicious HTTP or HTTPS requests, exposing systems to significant risk. It affects multiple versions of both FortiManager and FortiAnalyzer across different series, making it critical for organizations to assess their systems and apply necessary mitigations.
Affected Version(s)
FortiAnalyzer 7.4.0 <= 7.4.2
FortiAnalyzer 7.2.0 <= 7.2.5
FortiAnalyzer 7.0.0 <= 7.0.13