Aller au contenu
appaloosa scout logo main rounded
MEDIUM 5.3

CVE-2024-48885

EN A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions, FortiWeb 6.4 all versions allows attacker to escalate privilege via specially crafted packets.

CVSS v3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS 0.3% percentile 52.8%

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
fortinet fortirecorder iOS ≥7.0.0 <7.0.5 cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*
fortinet fortirecorder iOS ≥7.2.0 <7.2.2 cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*
Voir sur NVD ↗