Multiple path traversal in administrative interface

Summary

Multiples improper limitations of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiClientEMS management interface may allow a remote and authenticated attacker to retrieve or delete arbitrary files from the underlying filesystem via specially crafted web requests.

Version Affected Solution
FortiClientEMS 7.4 Not affected Not Applicable
FortiClientEMS 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS 7.0 7.0 all versions Migrate to a fixed release
FortiClientEMS 6.4 6.4 all versions Migrate to a fixed release
FortiClientEMS 6.2 6.2 all versions Migrate to a fixed release
FortiClientEMS 6.0 6.0 all versions Migrate to a fixed release
FortiClientEMS 1.2 1.2.2 through 1.2.5 Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Timeline

2024-09-10: Initial publication