VDB
CVE-2024-35274
CVE-2024-35274
PUBLISHED
Es besteht eine Schwachstelle in Fortinet FortiAnalyzer und Fortinet FortiManager. Die Sicherheitslücke besteht aufgrund einer fehlerhaften Dateipfadbeschränkung, die eingeschränkte Directories nicht ausreichend durchsetzt. Ein lokaler Angreifer mit Administratorzugriff kann diese Schwachstelle ausnutzen, um über manipulierte CLI-Anfragen Dateien in bestimmten Directories zu erstellen.
EPSS 0.06% · 18.6th percentile
Risk Scores
EPSS Score
0.06%
18.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortinet FortiManager <7.2.6 | |
| Fortinet | Fortinet FortiAnalyzer <7.0.13 | |
| Fortinet | Fortinet FortiManager <7.4.3 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.2.7 | |
| Fortinet | Fortinet FortiAnalyzer <7.4.3 | |
| Fortinet | Fortinet FortiManager <6.4.15 | |
| Fortinet | Fortinet FortiAnalyzer <6.4.15 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.4.1 | |
| Fortinet | Fortinet FortiAnalyzer <7.2.6 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.2.8 | |
| Fortinet | Fortinet FortiAnalyzer BigData <7.2.6 | |
| Fortinet | Fortinet FortiManager <7.0.13 |
Timeline
- Nov 12, 2024 Coalition ESS Score
- Nov 12, 2024 CVE Published
- Nov 12, 2024 PoC Published
- Nov 13, 2024 EPSS Score
- Nov 13, 2024 Coalition ESS Score
- Nov 13, 2024 PoC Published
- Dec 2, 2024 EPSS Score
- Dec 19, 2024 EPSS Score
- Jan 6, 2025 EPSS Score
- Jan 21, 2025 Coalition ESS Score
- Jan 23, 2025 EPSS Score
- Feb 10, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3447.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3447 advisory
- https://www.fortiguard.com/psirt/FG-IR-23-267 advisory
- https://www.fortiguard.com/psirt/FG-IR-23-396 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-098 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-099 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-115 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-116 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-125 advisory
- https://www.fortiguard.com/psirt/FG-IR-24-179 advisory