FG-IR-24-115: Arbitrary file read in administrative interface
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-115?
The FG-IR-24-115 vulnerability is classified as a critical severity issue due to its potential to allow privileged attackers to read arbitrary files.
How do I fix FG-IR-24-115?
To fix FG-IR-24-115, upgrade FortiManager or FortiAnalyzer to the specified remedial versions, such as 7.4.3 for FortiManager.
Which products are affected by FG-IR-24-115?
The FG-IR-24-115 vulnerability affects FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData across several versions.
What type of vulnerability is FG-IR-24-115?
FG-IR-24-115 is a Path Traversal vulnerability that allows unauthorized access to files in a restricted directory.
Is there a workaround for FG-IR-24-115?
There is no known workaround for FG-IR-24-115, and users are advised to apply the necessary updates.