CVE-2024-32116: Path traversal vulnerability in CLI commands
Multiple relative path traversal vulnerabilities [CWE-23] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Other sources
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32116?
CVE-2024-32116 has a high severity rating due to its potential to allow privileged attackers to delete files from the filesystem.
How do I fix CVE-2024-32116?
To fix CVE-2024-32116, upgrade FortiManager and FortiAnalyzer to version 7.4.3 or later, or follow recommended remediation steps for affected versions.
Which products are affected by CVE-2024-32116?
CVE-2024-32116 affects FortiAnalyzer and FortiManager versions specifically between 6.2.0 and 7.4.2.
Can I mitigate CVE-2024-32116 without upgrading?
Mitigation may be limited, but implementing strict access controls could reduce the likelihood of exploitation.
Is there a known exploit for CVE-2024-32116?
While there are no public reports of active exploitation of CVE-2024-32116, its vulnerabilities create a significant risk for affected systems.