Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiMail version 7.6.0 through 7.6.1 and before 7.4.3, FortiVoice version 7.0.0 through 7.0.5 and before 7.4.9, FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4, FortiCamera & FortiNDR version 7.6.0 and before 7.4.6 may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.
2025-08-12T19:15:27.397
2025-08-14T01:14:41.250
Analyzed
CVSSv3.1: 4.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | fortinet | forticamera_firmware | ≤ 2.1.4 | Yes |
| Hardware | fortinet | forticamera | - | No |
| Application | fortinet | fortimail | < 7.4.4 | Yes |
| Application | fortinet | fortimail | < 7.6.2 | Yes |
| Application | fortinet | fortindr | < 7.4.7 | Yes |
| Application | fortinet | fortindr | < 7.6.2 | Yes |
| Application | fortinet | fortirecorder | < 7.0.5 | Yes |
| Application | fortinet | fortirecorder | < 7.2.2 | Yes |
| Application | fortinet | fortivoice | < 6.4.10 | Yes |
| Application | fortinet | fortivoice | < 7.0.5 | Yes |