CVE-2024-48884: Fortinet FortiManager

Critical severity, CVSS 9.1. EPSS: 15.3% chance of exploitation in the next 30 days.

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, FortiProxy 7.2.0 through 7.2.11, FortiProxy 7.0.0 through 7.0.18, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions may allow a remote authenticated attacker with access to the security fabric interface and port to write arbitrary files or a remote unauthenticated attacker to delete an arbitrary folder

Affected products

  • Fortinet FortiManager: from 7.4.1, before 7.4.4 (fixed in 7.4.4); from 7.6.0, before 7.6.2 (fixed in 7.6.2)
  • Fortinet FortiManager Cloud: from 7.4.1, before 7.4.4 (fixed in 7.4.4)
  • Fortinet FortiOS: from 6.4.0, before 6.4.16 (fixed in 6.4.16); from 7.0.0, before 7.0.16 (fixed in 7.0.16); from 7.2.0, before 7.2.10 (fixed in 7.2.10); from 7.4.0, before 7.4.5 (fixed in 7.4.5); version 7.6.0 only
  • Fortinet FortiProxy: from 1.0.0, before 7.0.19 (fixed in 7.0.19); from 7.2.0, before 7.2.12 (fixed in 7.2.12); from 7.4.0, before 7.4.6 (fixed in 7.4.6)
  • Fortinet Fortirecorder: from 7.0.0, before 7.0.5 (fixed in 7.0.5); from 7.2.0, before 7.2.2 (fixed in 7.2.2)
  • Fortinet Fortivoice: from 6.0.0, up to and including 6.4.10; from 7.0.0, up to and including 7.0.5
  • Fortinet FortiWeb: from 6.4.0, before 7.4.5 (fixed in 7.4.5); version 7.6.0 only

Published 2025-01-14. Last modified 2026-07-08.