CVE-2023-37932: Path Traversal
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37932?
CVE-2023-37932 has a high severity rating due to the potential for an authenticated attacker to exploit the vulnerability and access sensitive files.
What software versions are affected by CVE-2023-37932?
CVE-2023-37932 affects FortiVoice versions 7.0.0, 6.4.0 through 6.4.7, and 6.0.0 through 6.0.12.
How do I fix CVE-2023-37932?
To fix CVE-2023-37932, upgrade FortiVoice to version 6.4.8 or later, or to version 7.0.1 or later.
What type of attack does CVE-2023-37932 enable?
CVE-2023-37932 enables a path traversal attack, allowing attackers to read arbitrary files from the system.
Is authentication required to exploit CVE-2023-37932?
Yes, CVE-2023-37932 requires the attacker to be authenticated to the FortiVoice system to exploit the vulnerability.