CVE-2024-36512: Arbitrary file write on GUI
A relative path traversal vulnerability [CWE-23] in FortiManager & FortiAnalyzer may allow a privileged attacker with super-admin profile and CLI access to write files on the underlying system via crafted HTTP or HTTPS requests.
Other sources
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36512?
CVE-2024-36512 has a severity rating that allows a privileged attacker to exploit a relative path traversal vulnerability.
How do I fix CVE-2024-36512?
To fix CVE-2024-36512, upgrade FortiManager or FortiAnalyzer to version 7.4.4 or later, 7.2.6 or later, or 7.0.13 or later.
Which products are affected by CVE-2024-36512?
CVE-2024-36512 affects FortiManager and FortiAnalyzer versions 6.2.10 up to 7.4.3.
Who is at risk for CVE-2024-36512?
Privileged attackers with super-admin profiles and CLI access are at risk of exploiting CVE-2024-36512.
What type of vulnerability is CVE-2024-36512?
CVE-2024-36512 is classified as a relative path traversal vulnerability.