CVE-2024-47566: Path Traversal
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47566?
CVE-2024-47566 has been rated as critical due to its potential to allow privileged attackers to delete essential files from the filesystem.
How do I fix CVE-2024-47566?
To mitigate CVE-2024-47566, update Fortinet FortiRecorder to a version higher than 7.2.1 or 7.0.4.
What kind of attack does CVE-2024-47566 enable?
CVE-2024-47566 enables a path traversal attack that allows attackers to manipulate file paths and delete files.
Which versions of Fortinet FortiRecorder are affected by CVE-2024-47566?
Fortinet FortiRecorder versions 7.2.0 to 7.2.1 and below 7.0.4 are affected by CVE-2024-47566.
What is the impact of exploiting CVE-2024-47566?
Exploiting CVE-2024-47566 can lead to unauthorized file deletions, potentially compromising the integrity of the system.