- Description
- A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, 6.4.0 through 6.4.3, FortiVoice versions 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.0 through 6.0.12 allows attacker to escalate privilege via specially crafted packets.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity
- CRITICAL
- psirt@fortinet.com
- CWE-22
- Hype score
- Not currently trending
FortiOS 7.6.x 7.6.0はCVEが7個 クリティカルなのは CVE-2024-54021 CVE-2024-48885 CVE-2024-48884 と9以上は3個 できるだけ最新が安全。
@g_yotuya
7 Feb 2025
304 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-48885 A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb… https://t.co/85fNSwZ5oB
@CVEnew
16 Jan 2025
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7269FDB6-A1D4-4912-8751-87BA52614FDA",
"versionEndExcluding": "7.4.4",
"versionStartIncluding": "7.4.1"
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "241A8930-4ADA-4380-AA42-F10B28487595",
"versionEndExcluding": "7.6.2",
"versionStartIncluding": "7.6.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "164DEDC3-B1C0-42AC-9ADB-CE03CF6A71CC",
"versionEndExcluding": "7.4.4",
"versionStartIncluding": "7.4.1"
},
{
"criteria": "cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32CFAF1E-358A-4F6D-96CB-D7229F0D9D74",
"versionEndExcluding": "7.0.19",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8B93C73-1E94-4854-8405-C3689860A74C",
"versionEndExcluding": "7.2.12",
"versionStartIncluding": "7.2.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B276403-CE85-445A-9E5D-BBFBD7AB7A68",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD60BA50-3F98-46BF-97E8-28AB207DE12A",
"versionEndExcluding": "7.0.5",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0B0D078-2F52-46B4-B9C0-162447828E1B",
"versionEndExcluding": "7.2.2",
"versionStartIncluding": "7.2.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBF1E214-4BC5-47E8-BF02-072D6D830BAF",
"versionEndIncluding": "6.4.10",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5EEE0DFA-DE31-4D26-AC98-6BCED8F008DC",
"versionEndIncluding": "7.0.5",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDB9CE13-AAF4-418C-BA26-1A0D53C5C1C2",
"versionEndExcluding": "7.4.5",
"versionStartIncluding": "6.4.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortiweb:7.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28B43375-DA74-4C5F-BAEE-39F312EEF51F"
},
{
"criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA0532A5-31F2-4A92-BF31-6003E28AC948",
"versionEndExcluding": "7.0.16",
"versionStartIncluding": "6.4.0"
},
{
"criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D7D031B-221B-4738-AC83-4FB92A106528",
"versionEndExcluding": "7.2.10",
"versionStartIncluding": "7.2.0"
},
{
"criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A71AD879-997D-4787-A1E9-E4132AC521E2",
"versionEndExcluding": "7.4.5",
"versionStartIncluding": "7.4.0"
},
{
"criteria": "cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44CE8EE3-D64A-49C8-87D7-C18B302F864A"
}
],
"operator": "OR"
}
]
}
]