CVE-2024-48885: Path traversal in csfd daemon
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions, FortiWeb 6.4 all versions allows attacker to escalate privilege via specially crafted packets.
Other sources
An improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in FortiManager, FortiOS, FortiProxy, FortiRecorder, FortiVoice and FortiWeb may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files and a remote unauthenticated attacker with the same network access to delete an arbitrary folder.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiSASEto a version that resolves this vulnerability.Fixed in 24.3.c - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 6.4.16 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.16 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.10 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.19 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.12 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.6 - Upgrade
Upgrade
FortiRecorderto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
FortiRecorderto a version that resolves this vulnerability.Fixed in 7.2.2 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 6.4.10 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.2.0 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiAuthenticatorto a version that resolves this vulnerability.Fixed in 7.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48885?
CVE-2024-48885 has a high severity due to its potential for path traversal vulnerabilities.
How do I fix CVE-2024-48885?
To fix CVE-2024-48885, upgrade affected Fortinet products to the recommended versions listed in the advisory.
Which products are affected by CVE-2024-48885?
CVE-2024-48885 affects multiple Fortinet products including FortiManager, FortiOS, FortiProxy, and FortiWeb.
What versions are vulnerable to CVE-2024-48885?
Versions ranging from FortiRecorder 7.2.0 to 7.2.1 and several versions of FortiWeb and FortiOS are vulnerable to CVE-2024-48885.
Is there a workaround for CVE-2024-48885?
There are no documented workarounds for CVE-2024-48885, hence updating to the latest versions is recommended.