A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.6.2Upgrade FortiManager to 7.4.4 | Feb 6, 2025 | Jan 14, 2025 |
| Fortinet Fortiproxy | — | Upgrade FortiProxy to 7.0.19Upgrade FortiProxy to 7.4.6Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 7.2.12 | Sep 30, 2026 | Jan 14, 2025 |
| Fortinet Fortiweb | — | Upgrade FortiWeb to 7.6.1Upgrade FortiWeb to 7.4.5Upgrade to the latest version of FortiWeb | Jul 2, 2026 | Jan 14, 2025 |
| Fortios | — | Upgrade FortiOS to 7.4.5Upgrade FortiOS to 7.2.10Upgrade FortiOS to 7.6.1Upgrade FortiOS to 7.0.16Upgrade FortiOS to 6.4.16 | Feb 6, 2025 | Jan 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub