CVE-2024-55597: Directory Traversal Arbitrary File Write Vulnerability
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests.
Other sources
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb API endpoint may allow an authenticated attacker with admin privileges to access and modify the filesystem.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55597?
CVE-2024-55597 is rated as a critical severity vulnerability.
How do I fix CVE-2024-55597?
To mitigate CVE-2024-55597, update Fortinet FortiWeb to a version higher than 7.6.0.
What does CVE-2024-55597 affect?
CVE-2024-55597 affects Fortinet FortiWeb versions 7.0.0 through 7.6.0.
What type of vulnerability is CVE-2024-55597?
CVE-2024-55597 is a path traversal vulnerability allowing unauthorized code execution.
Can CVE-2024-55597 be exploited remotely?
Yes, CVE-2024-55597 can be exploited remotely via crafted requests.