Analyse på rafaelpfister.ch

Produsentens beskrivelse (engelsk)

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Referansedata

Produsent
Fortinet
Berørte produkter
  • FortiMail
CVSS 3.1
9.8 (CRITICAL)
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Type svakhet
CWE-22: Path Traversal
Publisert
1. oktober 2026
I KEV-katalogen siden
1. oktober 2026
Frist amerikanske føderale etater
4. oktober 2026

Offisielle kilder

← Alle sårbarheter