Path Traversal Vulnerability in Fortinet FortiRecorder, FortiWeb, and FortiVoice
CVE-2024-48885
9.1CRITICAL
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 16 January 2025
Summary
A path traversal vulnerability has been identified in Fortinet's FortiRecorder, FortiWeb, and FortiVoice products, allowing attackers to exploit improper limitations on file paths. This flaw affects multiple versions of these products, enabling unauthorized privilege escalation through the use of specially crafted packets. Users of the affected versions are encouraged to apply updates and follow security best practices to mitigate potential risks.
Affected Version(s)
FortiRecorder 7.2.0 <= 7.2.1
FortiRecorder 7.0.0 <= 7.0.4
FortiVoice 7.0.0 <= 7.0.4
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved