CVE-2024-35274: Path traversal vulnerability leading to file creation
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiAnalyzer, FortiManager and FortiAnalyzer-BigData may allow a privileged attacker with read write administrative privileges to create non-arbitrary files on a chosen directory via crafted CLI requests.
Other sources
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write administrative privileges to create non-arbitrary files on a chosen directory via crafted CLI requests.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35274?
CVE-2024-35274 is classified with a high severity due to its potential impact in allowing privileged attacks.
How do I fix CVE-2024-35274?
To mitigate CVE-2024-35274, upgrade FortiAnalyzer and FortiManager to version 7.4.3 or later.
Which versions are affected by CVE-2024-35274?
CVE-2024-35274 affects FortiAnalyzer versions from 6.2 to 7.4.2 and FortiManager versions from 6.2 to 7.4.2.
Who is the vendor for CVE-2024-35274?
The vendor for CVE-2024-35274 is Fortinet, which develops FortiAnalyzer and FortiManager.
What type of vulnerability is CVE-2024-35274?
CVE-2024-35274 is a path traversal vulnerability that allows potential unauthorized file access.