CVE-2025-60024

8.8

Fortinet · FortiVoice

Fortinet FortiVoice contains multiple path traversal vulnerabilities that allow a privileged authenticated attacker to write arbitrary files via HTTP or HTTPS commands.

Executive summary

A path traversal vulnerability in Fortinet FortiVoice allows authenticated attackers to achieve arbitrary file writes, creating a significant risk of system compromise.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) that allows a privileged authenticated attacker to manipulate file paths and write arbitrary files to the underlying system. The attack is triggered via specially crafted HTTP or HTTPS commands.

Business impact

Successful exploitation of this vulnerability permits an attacker to perform arbitrary file writes on the affected FortiVoice system. With a CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, unauthorized configuration changes, or the injection of malicious code. Such access severely threatens the integrity and availability of communication services managed by the platform.

Remediation

Immediate Action: Upgrade FortiVoice to version 7.2.3 or 7.0.8 or above immediately to resolve the vulnerability.

Proactive Monitoring: Monitor system access logs for anomalous HTTP or HTTPS requests that contain directory traversal patterns or unexpected file modification attempts.

Compensating Controls: Ensure that administrative access to the FortiVoice interface is restricted to trusted internal networks only, and consider implementing strict WAF rules to filter malicious payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for arbitrary file write operations, this vulnerability must be treated as a priority for all administrators managing affected FortiVoice instances. Organizations should schedule the recommended firmware upgrades during the next maintenance window to ensure full remediation of the underlying path traversal flaw.

More Fortinet CVEs

Sources