FG-IR-24-179: Path traversal vulnerability leading to file creation
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiAnalyzer, FortiManager and FortiAnalyzer-BigData may allow a privileged attacker with read write administrative privileges to create non-arbitrary files on a chosen directory via crafted CLI requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-179?
The severity of FG-IR-24-179 is critical due to the potential for attackers to create non-arbitrary files in restricted directories.
How do I fix FG-IR-24-179?
To fix FG-IR-24-179, update FortiAnalyzer and FortiManager to version 7.4.3 or later, or follow recommended remedies for affected versions.
Which products are affected by FG-IR-24-179?
FG-IR-24-179 affects FortiAnalyzer and FortiManager versions 6.2 to 7.4.2.
Can FG-IR-24-179 be exploited remotely?
Yes, FG-IR-24-179 can be exploited remotely by privileged attackers with administrative access.
What is the nature of the vulnerability in FG-IR-24-179?
FG-IR-24-179 is a path traversal vulnerability that allows privileged attackers to manipulate file paths.