Path Traversal Vulnerability in Fortinet FortiManager and FortiAnalyzer
CVE-2024-36508

5.9MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
11 February 2025

Summary

An improper limitation of a pathname vulnerability exists in Fortinet FortiManager and FortiAnalyzer, allowing an authenticated administrator with diagnose privileges to exploit this flaw. This vulnerability enables the deletion of files from the system, which can lead to significant security concerns. System administrators should ensure their installations are updated to the latest versions to mitigate these risks.

Affected Version(s)

FortiAnalyzer 7.4.0 <= 7.4.2

FortiAnalyzer 7.2.0 <= 7.2.5

FortiAnalyzer 7.0.0 <= 7.0.13

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.