Analisi su rafaelpfister.ch

Descrizione del produttore (in inglese)

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Dati di riferimento

Produttore
Fortinet
Prodotti interessati
  • FortiMail
CVSS 3.1
9.8 (CRITICAL)
Vettore
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Tipo di debolezza
CWE-22: Path Traversal
Pubblicata
1 ottobre 2026
Nel catalogo KEV dal
1 ottobre 2026
Scadenza enti federali USA
4 ottobre 2026

Fonti ufficiali

← Tutte le vulnerabilità