PT-2024-8518 · Fortinet · Fortianalyzer+2

Published

2024-11-12

·

Updated

2025-01-21

·

CVE-2024-32116

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiManager versions 7.4.0 through 7.4.2 and prior to 7.2.5 FortiAnalyzer versions 7.4.0 through 7.4.2 and prior to 7.2.5 FortiAnalyzer-BigData versions 7.4.0 and prior to 7.2.7
Description The issue is related to errors in handling relative paths to directories in the Command Line Interface (CLI) of Fortinet FortiManager and FortiAnalyzer, as well as FortiAnalyzer-BigData. This allows a remote attacker to delete arbitrary files in the file system by sending specially crafted requests. The vulnerability can be exploited by a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Recommendations For FortiManager versions 7.4.0 through 7.4.2 and prior to 7.2.5, update to a version that includes the fix for this issue. For FortiAnalyzer versions 7.4.0 through 7.4.2 and prior to 7.2.5, update to a version that includes the fix for this issue. For FortiAnalyzer-BigData versions 7.4.0 and prior to 7.2.7, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CLI interface to minimize the risk of exploitation.

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

BDU:2024-10078
CVE-2024-32116

Affected Products

Fortianalyzer
Fortianalyzer-Bigdata
Fortimanager