CVE-2023-25606

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4  all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fortinetfortianalyzer
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortianalyzer
7.0.0 ≤
𝑥
≤ 7.0.5
fortinetfortianalyzer
7.2.0 ≤
𝑥
< 7.2.2
fortinetfortimanager
6.4.0 ≤
𝑥
< 6.4.12
fortinetfortimanager
7.0.0 ≤
𝑥
≤ 7.0.5
fortinetfortimanager
7.2.0 ≤
𝑥
< 7.2.2
𝑥
= Vulnerable software versions