CVE-2024-47566
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete
Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.002
9.1th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet
Description
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiRecorder | Other Products | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiRecorder
Vendor remediation
Please upgrade to FortiRecorder version 7.2.2 or above Please upgrade to FortiRecorder version 7.0.5 or above