CVE-2024-48885

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 throug

Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.008
52.3th percentile
Discovered by
Not disclosed
Published
Jan 16, 2025
Assigned by fortinet

Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions, FortiWeb 6.4 all versions allows attacker to escalate privilege via specially crafted packets.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Fortinet FortiRecorder Other Products cna-assigner
Fortinet FortiVoice Other Products cna-assigner
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported affected versions (3)
  • Fortinet · FortiVoice
  • Fortinet · FortiRecorder
  • Fortinet · FortiWeb

Vendor remediation

Upgrade to upcoming FortiAuthenticator version 7.0.0 or above Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.5 or above Upgrade to FortiOS version 7.2.10 or above Upgrade to FortiOS version 7.0.16 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiWeb version 7.6.1 or above Upgrade to FortiWeb version 7.4.5 or above Upgrade to FortiRecorder version 7.2.2 or above Upgrade to FortiRecorder version 7.0.5 or above Upgrade to FortiManager Cloud version 7.4.4 or above Upgrade to FortiProxy version 7.4.6 or above Upgrade to FortiProxy version 7.2.12 or above Upgrade to FortiProxy version 7.0.19 or above Upgrade to FortiVoice version 7.2.0 or above Upgrade to FortiVoice version 7.0.5 or above Upgrade to FortiVoice version 6.4.10 or above Fortinet remediated this issue in FortiSASE version 24.3.c and hence customers do not need to perform any action. Upgrade to FortiManager version 7.6.2 or above Upgrade to FortiManager version 7.4.4 or above