Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiClientEMS version 7.4.0 or above Please upgrade to FortiClientEMS version 7.2.5 or above
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19367 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests |
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-362 |
|
Wed, 25 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlient Endpoint Management Server |
|
| CPEs | cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlient Endpoint Management Server |
Tue, 10 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-10T18:58:32.329Z
Reserved: 2024-01-02T10:15:00.526Z
Link: CVE-2024-21753
Updated: 2024-09-10T18:58:26.422Z
Status : Analyzed
Published: 2024-09-10T15:15:14.543
Modified: 2024-09-25T18:36:45.307
Link: CVE-2024-21753
No data.
OpenCVE Enrichment
No data.
EUVD