Fortinet FortiManager
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*, +1 more
- >= 7.4.0, <= 7.4.2
- >= 7.2.0, <= 7.2.5
- >= 7.0.0, <= 7.0.12
- >= 6.4.0, <= 6.4.14
- >= 6.2.0, <= 6.2.12
- >= 6.0.0, <= 6.0.12
A path traversal vulnerability has been identified in Fortinet FortiManager and FortiAnalyzer. Affected versions include FortiManager and FortiAnalyzer 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.12, and 6.0.0 through 6.0.12. This vulnerability allows attackers to execute unauthorized code or commands by sending crafted HTTP or HTTPS requests that exploit the improper limitation of pathnames to restricted directories.
Exploitation of this vulnerability could lead to unauthorized code execution on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.