Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-48885


A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, 6.4.0 through 6.4.3, FortiVoice versions 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.0 through 6.0.12 allows attacker to escalate privilege via specially crafted packets.


Published

2025-01-16T09:15:06.737

Last Modified

2025-02-03T21:11:41.750

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortimanager < 7.4.4 Yes
Application fortinet fortimanager < 7.6.2 Yes
Application fortinet fortimanager_cloud < 7.4.4 Yes
Application fortinet fortiproxy < 7.0.19 Yes
Application fortinet fortiproxy < 7.2.12 Yes
Application fortinet fortiproxy < 7.4.6 Yes
Application fortinet fortirecorder < 7.0.5 Yes
Application fortinet fortirecorder < 7.2.2 Yes
Application fortinet fortivoice ≤ 6.4.10 Yes
Application fortinet fortivoice ≤ 7.0.5 Yes
Application fortinet fortiweb < 7.4.5 Yes
Application fortinet fortiweb 7.6.0 Yes
Operating System fortinet fortios < 7.0.16 Yes
Operating System fortinet fortios < 7.2.10 Yes
Operating System fortinet fortios < 7.4.5 Yes
Operating System fortinet fortios 7.6.0 Yes

References