imPC@ndo IT

Tracker / CVE-2024-40588

CVE-2024-40588

Medium 4.4

Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.6, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiRecorder 6.4 all versions, FortiVoice 7.0.0 through 7.0.3, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.

Affected products and versions

fortinet forticamera_firmware · 2.0.0 → 2.1.4
fortinet fortimail · 6.4.0 → 7.4.4
fortinet fortimail · 7.6.0 → 7.6.2
fortinet fortindr · 7.0.0 → 7.4.7
fortinet fortindr · 7.6.0 → 7.6.2
fortinet fortirecorder · 6.4.0 → 7.0.5
fortinet fortirecorder · 7.2.0 → 7.2.2
fortinet fortivoice · 6.0.0 → 6.4.10
fortinet fortivoice · 7.0.0 → 7.0.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References