Path Traversal Vulnerability in Fortinet FortiRecorder, FortiWeb, and FortiVoice
CVE-2024-48885

5.2MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
16 January 2025

Summary

A path traversal vulnerability has been identified in Fortinet's FortiRecorder, FortiWeb, and FortiVoice products, allowing attackers to exploit improper limitations on file paths. This flaw affects multiple versions of these products, enabling unauthorized privilege escalation through the use of specially crafted packets. Users of the affected versions are encouraged to apply updates and follow security best practices to mitigate potential risks.

Affected Version(s)

FortiRecorder 7.2.0 <= 7.2.1

FortiRecorder 7.0.0 <= 7.0.4

FortiVoice 7.0.0 <= 7.0.4

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.