{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T15:35:29.369","vulnerabilities":[{"cve":{"id":"CVE-2024-32117","sourceIdentifier":"psirt@fortinet.com","published":"2024-11-12T19:15:09.073","lastModified":"2025-01-21T22:19:39.353","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests."},{"lang":"es","value":"Una vulnerabilidad de limitación incorrecta de una ruta de acceso a un directorio restringido ('Path Traversal') [CWE-22] en Fortinet FortiManager versión 7.4.0 a 7.4.2 y anteriores 7.2.5, FortiAnalyzer versión 7.4.0 a 7.4.2 y anteriores 7.2.5 y FortiAnalyzer-BigData versión 7.4.0 y anteriores 7.2.7 permite a un atacante privilegiado leer archivos arbitrarios del sistema subyacente a través de solicitudes HTTP o HTTPS manipuladas. "}],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@fortinet.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndExcluding":"7.2.6","matchCriteriaId":"FF6CA5B2-29DE-4FB3-8D7D-D248A593AB79"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*","versionStartIncluding":"7.4.0","versionEndExcluding":"7.4.3","matchCriteriaId":"AF309EFD-1770-44AF-B192-3D9816F792CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortianalyzer_big_data:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.1","versionEndExcluding":"7.2.8","matchCriteriaId":"1A9C272F-2E14-4BC3-B3A3-1EF4E93BDBFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortianalyzer_big_data:7.4.0:*:*:*:*:*:*:*","matchCriteriaId":"80598594-A45A-4E69-B968-1DD3DBD30FF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndExcluding":"7.2.6","matchCriteriaId":"A3F113AF-AA71-466D-9841-15A5243ECFF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*","versionStartIncluding":"7.4.0","versionEndExcluding":"7.4.3","matchCriteriaId":"E4490512-36ED-4212-9D34-D74739A56E84"}]}]}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-115","source":"psirt@fortinet.com","tags":["Vendor Advisory"]}]}}]}