CVE-2024-36508: Fortinet Fortianalyzer

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.

Affected products

  • Fortinet Fortianalyzer: from 6.4.0, before 7.2.6 (fixed in 7.2.6); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
  • Fortinet FortiManager: from 6.4.0, before 7.2.6 (fixed in 7.2.6); from 7.4.0, before 7.4.3 (fixed in 7.4.3)

Published 2025-02-11. Last modified 2026-06-17.