FG-IR-24-097: Arbitrary file deletion in administrative interface
Published Jan 14, 2025
·Updated
A relative path traversal vulnerability [CWE-23] in FortiManager administrative interface may allow a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Affected Software
3 affected componentsFixes available
Fortinet FortiManager>=7.4.0<=7.4.2
Fortinet FortiManager>=7.2.0<=7.2.5
Fortinet FortiManager>=7.0
Event History
Jan 14, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-097?
The severity of FG-IR-24-097 is critical due to its potential to allow privileged attackers to delete files.
2
How do I fix FG-IR-24-097?
To fix FG-IR-24-097, upgrade FortiManager to versions 7.4.3 or 7.2.6 or later depending on your current version.
3
Which versions of FortiManager are affected by FG-IR-24-097?
FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, and all versions from 7.0 are affected by FG-IR-24-097.
4
What kind of attacks does FG-IR-24-097 allow?
FG-IR-24-097 allows attackers to perform a relative path traversal, potentially deleting files from the underlying filesystem.
5
Who is the vendor for FG-IR-24-097?
The vendor for FG-IR-24-097 is Fortinet, which develops the FortiManager product.