Path Traversal Vulnerability in Fortinet FortiRecorder, FortiWeb, and FortiVoice
CVE-2024-48885
5.2MEDIUM
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 16 January 2025
Summary
A path traversal vulnerability has been identified in Fortinet's FortiRecorder, FortiWeb, and FortiVoice products, allowing attackers to exploit improper limitations on file paths. This flaw affects multiple versions of these products, enabling unauthorized privilege escalation through the use of specially crafted packets. Users of the affected versions are encouraged to apply updates and follow security best practices to mitigate potential risks.
Affected Version(s)
FortiRecorder 7.2.0 <= 7.2.1
FortiRecorder 7.0.0 <= 7.0.4
FortiVoice 7.0.0 <= 7.0.4
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved