CVE-2024-21753
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9
Severity
Medium 5.5
CVSS 3.1
Exploited
Not listed
EPSS
0.007
51.1th percentile
Discovered by
Not disclosed
Published
Sep 10, 2024
Assigned by fortinet
Description
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiClientEMS
Vendor remediation
Please upgrade to FortiClientEMS version 7.4.0 or above Please upgrade to FortiClientEMS version 7.2.5 or above