CVE-2024-40588: Path Traversal
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.6, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiRecorder 6.4 all versions, FortiVoice 7.0.0 through 7.0.3, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40588?
CVE-2024-40588 is considered a high-severity vulnerability due to its potential for exploitation through path traversal.
How do I fix CVE-2024-40588?
To fix CVE-2024-40588, upgrade affected Fortinet products to the latest versions that are not impacted by the vulnerability.
Which versions are affected by CVE-2024-40588?
CVE-2024-40588 affects FortiMail versions 7.6.0 through 7.6.1 and versions before 7.4.3, FortiVoice versions 7.0.0 through 7.0.5 and before 7.4.9, FortiRecorder versions 7.2.0 through 7.2.1 and before 7.0.4, and FortiCamera & FortiNDR versions before 7.4.6.
What kind of vulnerability is CVE-2024-40588?
CVE-2024-40588 is a multiple relative path traversal vulnerability classified under CWE-23.
What products are impacted by CVE-2024-40588?
CVE-2024-40588 impacts Fortinet products including FortiMail, FortiVoice, FortiRecorder, FortiCamera, and FortiNDR.