CVE-2023-25606

EUVD-2023-29547
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4  all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
fortinetCNA
6.2 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:X/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
fortinetfortianalyzer
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortianalyzer
7.0.0 ≤
𝑥
≤ 7.0.5
fortinetfortianalyzer
7.2.0 ≤
𝑥
< 7.2.2
fortinetfortimanager
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortimanager
7.0.0 ≤
𝑥
≤ 7.0.5
fortinetfortimanager
7.2.0 ≤
𝑥
< 7.2.2
𝑥
= Vulnerable software versions