VDB
CVE-2024-32117
CVE-2024-32117
PUBLISHED
Es besteht eine Schwachstelle in Fortinet FortiAnalyzer und Fortinet FortiManager. Die Schwachstelle ist auf ein Path-Traversal-Problem zurückzuführen, das dazu führt, dass Einschränkungen für Directories nicht korrekt durchgesetzt werden. Ein authentisierter Angreifer mit privilegiertem Zugriff kann diese Schwachstelle ausnutzen, um beliebige Dateien aus dem unterliegenden System zu lesen, indem er manipulierte HTTP- oder HTTPS-Anfragen sendet.
EPSS 0.37% · 59.4th percentile
Risk Scores
EPSS Score
0.37%
59.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortinet FortiManager <7.2.6 | |
| Fortinet | Fortinet FortiManager <6.4.15 | |
| Fortinet | Fortinet FortiAnalyzer <7.4.3 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.2.7 | |
| Fortinet | Fortinet FortiAnalyzer <6.4.15 | |
| Fortinet | Fortinet FortiAnalyzer <7.2.6 | |
| Fortinet | Fortinet FortiAnalyzer <7.0.13 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.4.1 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.2.6 | |
| Fortinet | Fortinet FortiManager <7.4.3 | |
| Fortinet | Fortinet FortiManager <7.0.13 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.2.8 |
Exploit Intelligence
- CIRCL seen: CVE-2024-32117 (circl-sighting)
- CIRCL seen: CVE-2024-32117 (circl-sighting)
- https://fortiguard.fortinet.com/psirt/FG-IR-24-115 (circl)
Timeline
- Nov 12, 2024 Coalition ESS Score
- Nov 12, 2024 CVE Published
- Nov 12, 2024 PoC Published
- Nov 13, 2024 EPSS Score
- Nov 13, 2024 Coalition ESS Score
- Nov 13, 2024 Coalition ESS Score
- Nov 13, 2024 PoC Published
- Dec 2, 2024 EPSS Score
- Dec 19, 2024 EPSS Score
- Jan 6, 2025 EPSS Score
- Jan 21, 2025 Coalition ESS Score
- Jan 21, 2025 Coalition ESS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3447.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3447 advisory
- https://www.fortiguard.com/psirt/FG-IR-23-267 advisory
- https://www.fortiguard.com/psirt/FG-IR-23-396 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-098 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-099 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-115 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-116 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-125 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-179 advisory