CVE-2024-48884: Path traversal in csfd daemon
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder
Other sources
An improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in FortiManager, FortiOS, FortiProxy, FortiRecorder, FortiVoice and FortiWeb may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files and a remote unauthenticated attacker with the same network access to delete an arbitrary folder.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 6.4.16 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.16 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.10 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.19 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.12 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.6 - Upgrade
Upgrade
FortiRecorderto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
FortiRecorderto a version that resolves this vulnerability.Fixed in 7.2.2 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 6.4.10 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.2.0 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiAuthenticatorto a version that resolves this vulnerability.Fixed in 7.0.0 - Compensating control
For FortiSASE, remediate by upgrading to FortiSASE version 24.3.c; customers do not need to perform any additional action if already on 24.3.c.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48884?
CVE-2024-48884 has been classified with a critical severity due to its potential impact on path traversal vulnerabilities.
Which versions are affected by CVE-2024-48884?
CVE-2024-48884 affects Fortinet FortiManager, FortiOS, FortiProxy, and FortiRecorder across multiple versions leading up to their respective patches.
How do I fix CVE-2024-48884?
To fix CVE-2024-48884, upgrade FortiManager to version 7.6.2 or later, and other affected products to their respective patched versions.
Can I still use my software if it is vulnerable to CVE-2024-48884?
Using software vulnerable to CVE-2024-48884 poses significant security risks, and immediate remediation through updates is strongly advised.
Are there workarounds available for CVE-2024-48884?
There are no known workarounds for CVE-2024-48884; updating the software is the only effective measure to mitigate the vulnerability.