FG-IR-24-259: Path traversal in csfd daemon
An improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in FortiManager, FortiOS, FortiProxy, FortiRecorder, FortiVoice and FortiWeb may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files and a remote unauthenticated attacker with the same network access to delete an arbitrary folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-259?
The severity of FG-IR-24-259 is considered high as it involves path traversal vulnerabilities that can allow remote attackers to access restricted directories.
How do I fix FG-IR-24-259?
To fix FG-IR-24-259, update affected Fortinet products to the recommended versions listed in the advisory.
Which versions are affected by FG-IR-24-259?
Versions of FortiManager, FortiOS, FortiProxy, FortiRecorder, FortiVoice, and FortiWeb prior to the mentioned remediation versions are affected by FG-IR-24-259.
Can FG-IR-24-259 be exploited remotely?
Yes, FG-IR-24-259 can be exploited by remote authenticated attackers with access to the security fabric interface.
Is authentication required to exploit FG-IR-24-259?
Yes, the exploit for FG-IR-24-259 requires the attacker to be authenticated.