CVE-2024-32117: Arbitrary file read in administrative interface
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.
Other sources
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32117?
CVE-2024-32117 is a high severity vulnerability that allows a privileged attacker to read arbitrary files from the system.
How do I fix CVE-2024-32117?
To mitigate CVE-2024-32117, upgrade FortiManager or FortiAnalyzer to the latest recommended version indicated in the vendor's advisory.
Which versions are affected by CVE-2024-32117?
CVE-2024-32117 affects multiple versions of FortiManager and FortiAnalyzer including versions up to 7.4.2.
What type of vulnerability is CVE-2024-32117?
CVE-2024-32117 is classified as a Path Traversal vulnerability, allowing unauthorized access to files.
Who is impacted by CVE-2024-32117?
Organizations using vulnerable versions of FortiManager or FortiAnalyzer are at risk due to CVE-2024-32117.