First published: Tue Jan 14 2025(Updated: )
A relative path traversal vulnerability [CWE-23] in FortiManager administrative interface may allow a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | >=7.4.0<=7.4.2 | |
Fortinet FortiManager | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | >=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-097 is critical due to its potential to allow privileged attackers to delete files.
To fix FG-IR-24-097, upgrade FortiManager to versions 7.4.3 or 7.2.6 or later depending on your current version.
FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, and all versions from 7.0 are affected by FG-IR-24-097.
FG-IR-24-097 allows attackers to perform a relative path traversal, potentially deleting files from the underlying filesystem.
The vendor for FG-IR-24-097 is Fortinet, which develops the FortiManager product.