CVE-2024-33502: Arbitrary file delete on firmware import image feature
A relative path traversal vulnerability [CWE-23] in FortiManager administrative interface may allow a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Other sources
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPs requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33502?
CVE-2024-33502 has a high severity due to its potential impact allowing privileged attackers to delete files from the filesystem.
How do I fix CVE-2024-33502?
To fix CVE-2024-33502, update FortiManager and FortiAnalyzer software to version 7.4.3 or later for affected versions.
Which versions of FortiManager are affected by CVE-2024-33502?
CVE-2024-33502 affects FortiManager versions below 7.4.3, especially 7.0 and earlier.
Which versions of FortiAnalyzer are impacted by CVE-2024-33502?
CVE-2024-33502 impacts FortiAnalyzer versions below 7.4.3, particularly those below 7.2.6.
What type of vulnerability is CVE-2024-33502?
CVE-2024-33502 is classified as a relative path traversal vulnerability, allowing potential unauthorized file deletion.