imPC@ndo EN

Tracker / CVE-2024-48884

CVE-2024-48884

Alta 7.5

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder

Prodotti e versioni affette

fortinet fortimanager · 7.4.1 → 7.4.4
fortinet fortimanager · 7.6.0 → 7.6.2
fortinet fortimanager_cloud · 7.4.1 → 7.4.4
fortinet fortios
fortinet fortios · 6.4.0 → 6.4.16
fortinet fortios · 7.0.0 → 7.0.16
fortinet fortios · 7.2.0 → 7.2.10
fortinet fortios · 7.4.0 → 7.4.5
fortinet fortiproxy · 1.0.0 → 7.0.19
fortinet fortiproxy · 7.2.0 → 7.2.12
fortinet fortiproxy · 7.4.0 → 7.4.6
fortinet fortirecorder · 7.0.0 → 7.0.5
fortinet fortirecorder · 7.2.0 → 7.2.2
fortinet fortivoice · 6.0.0 → 6.4.10
fortinet fortivoice · 7.0.0 → 7.0.5
fortinet fortiweb
fortinet fortiweb · 6.4.0 → 7.4.5

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti