CVE-2024-32115: Arbitrary file deletion in administrative interface
A relative path traversal vulnerability [CWE-23] in FortiManager administrative interface may allow a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Other sources
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32115?
CVE-2024-32115 has been classified as a high severity vulnerability due to the potential for a privileged attacker to delete critical files.
How do I fix CVE-2024-32115?
To remediate CVE-2024-32115, upgrade FortiManager to version 7.4.3 or 7.2.6 or later.
What products are affected by CVE-2024-32115?
CVE-2024-32115 affects Fortinet FortiManager versions 7.4.0 to 7.4.2 and 7.2.0 to 7.2.5, as well as versions from 7.0 upwards.
What type of vulnerability is CVE-2024-32115?
CVE-2024-32115 is a relative path traversal vulnerability that can lead to unauthorized file deletion.
Can CVE-2024-32115 be exploited remotely?
Yes, CVE-2024-32115 can be exploited remotely through crafted HTTP or HTTPS requests.