vulnerability
Fortinet FortiAnalyzer: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2024-36508)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:L/AC:L/Au:M/C:N/I:C/A:C) | Aug 1, 2025 | Aug 1, 2025 | Aug 1, 2025 |
Severity
6
CVSS
(AV:L/AC:L/Au:M/C:N/I:C/A:C)
Published
Aug 1, 2025
Added
Aug 1, 2025
Modified
Aug 1, 2025
Description
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
Solutions
fortinet-fortianalyzer-upgrade-7_2_6fortinet-fortianalyzer-upgrade-7_4_3
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.