PT-2024-8518 · Fortinet · Fortianalyzer+2
Published
2024-11-12
·
Updated
2025-01-21
·
CVE-2024-32116
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiManager versions 7.4.0 through 7.4.2 and prior to 7.2.5
FortiAnalyzer versions 7.4.0 through 7.4.2 and prior to 7.2.5
FortiAnalyzer-BigData versions 7.4.0 and prior to 7.2.7
Description
The issue is related to errors in handling relative paths to directories in the Command Line Interface (CLI) of Fortinet FortiManager and FortiAnalyzer, as well as FortiAnalyzer-BigData. This allows a remote attacker to delete arbitrary files in the file system by sending specially crafted requests. The vulnerability can be exploited by a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Recommendations
For FortiManager versions 7.4.0 through 7.4.2 and prior to 7.2.5, update to a version that includes the fix for this issue.
For FortiAnalyzer versions 7.4.0 through 7.4.2 and prior to 7.2.5, update to a version that includes the fix for this issue.
For FortiAnalyzer-BigData versions 7.4.0 and prior to 7.2.7, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the CLI interface to minimize the risk of exploitation.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortianalyzer
Fortianalyzer-Bigdata
Fortimanager