An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
2023-07-11T17:15:12.780
2024-11-21T07:49:49.153
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortianalyzer | < 6.4.12 | Yes |
Application | fortinet | fortianalyzer | ≤ 7.0.5 | Yes |
Application | fortinet | fortianalyzer | < 7.2.2 | Yes |
Application | fortinet | fortimanager | < 6.4.12 | Yes |
Application | fortinet | fortimanager | ≤ 7.0.5 | Yes |
Application | fortinet | fortimanager | < 7.2.2 | Yes |