PT-2025-1181 · Fortinet · Fortirecorder+3

Published

2025-01-14

·

Updated

2026-01-14

·

CVE-2024-48885

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiRecorder versions 7.2.0 through 7.2.1 FortiRecorder versions 7.0.0 through 7.0.4 FortiWeb versions 7.6.0 FortiWeb versions 7.4.0 through 7.4.4 FortiWeb versions 7.2.0 through 7.2.10 FortiWeb versions 7.0.0 through 7.0.10 FortiWeb versions 6.4.0 through 6.4.3 FortiVoice versions 7.0.0 through 7.0.4 FortiVoice versions 6.4.0 through 6.4.9 FortiVoice versions 6.0.0 through 6.0.12
Description The issue is related to an improper limitation of a pathname to a restricted directory, also known as 'path traversal'. This allows an attacker to escalate privileges via specially crafted packets. A remote authenticated attacker with access to the security fabric interface and port may be able to write arbitrary files, and a remote unauthenticated attacker with the same network access may be able to delete an arbitrary folder.
Recommendations For FortiRecorder versions 7.2.0 through 7.2.1, update to a version outside of this range to mitigate the risk. For FortiRecorder versions 7.0.0 through 7.0.4, update to a version outside of this range to mitigate the risk. For FortiWeb versions 7.6.0, update to a version outside of this specific version to mitigate the risk. For FortiWeb versions 7.4.0 through 7.4.4, update to a version outside of this range to mitigate the risk. For FortiWeb versions 7.2.0 through 7.2.10, update to a version outside of this range to mitigate the risk. For FortiWeb versions 7.0.0 through 7.0.10, update to a version outside of this range to mitigate the risk. For FortiWeb versions 6.4.0 through 6.4.3, update to a version outside of this range to mitigate the risk. For FortiVoice versions 7.0.0 through 7.0.4, update to a version outside of this range to mitigate the risk. For FortiVoice versions 6.4.0 through 6.4.9, update to a version outside of this range to mitigate the risk. For FortiVoice versions 6.0.0 through 6.0.12, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the security fabric interface and port to minimize the risk of exploitation.

Fix

LPE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00464
CVE-2024-48885

Affected Products

Fortirecorder
Fortivoice
Fortiweb
Fortios