CVE-2024-36508

MEDIUM

Fortinet FortiManager <7.4.2, FortiAnalyzer <7.2.5 - Path Traversal

Title source: llm
STIX 2.1

Description

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.

References (1)

Core 1
Core References

Scores

CVSS v3 6.0
EPSS 0.0011
EPSS Percentile 28.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
fortinet/fortianalyzer 6.4.0 - 7.2.6
fortinet/fortimanager 6.4.0 - 7.2.6
Published Feb 11, 2025
Tracked Since Feb 18, 2026