PT-2025-20902 · Fortinet · Forticlientems+1

Published

2025-05-13

·

Updated

2025-05-13

·

CVE-2025-22859

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FortiClientEMS versions 7.4.0 through 7.4.1 FortiClientEMS Cloud versions 7.4.0 through 7.4.1
Description: A Relative Path Traversal issue may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.
Recommendations: For FortiClientEMS versions 7.4.0 through 7.4.1, consider restricting access to upload requests until a patch is available. For FortiClientEMS Cloud versions 7.4.0 through 7.4.1, consider restricting access to upload requests until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Weakness Enumeration

Related Identifiers

BDU:2025-11358
CVE-2025-22859

Affected Products

Forticlientems
Forticlientems Cloud