Análisis en rafaelpfister.ch

Descripción del fabricante (en inglés)

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Datos de referencia

Fabricante
Fortinet
Productos afectados
  • FortiMail
CVSS 3.1
9.8 (CRITICAL)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Tipo de debilidad
CWE-22: Path Traversal
Publicada
1 de octubre de 2026
En el catálogo KEV desde
1 de octubre de 2026
Plazo agencias federales de EE. UU.
4 de octubre de 2026

Fuentes oficiales

← Todas las vulnerabilidades