Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54659

Опубликовано: 10 мар. 2026
Источник: nvd
CVSS3: 5.8
CVSS3: 7.5
EPSS Низкий

Описание

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00465
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.8
github
5 месяцев назад

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.

CVSS3: 5.8
fstec
5 месяцев назад

Уязвимость программного обеспечения Fortinet FortiSOAR Agent Communication Bridge, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 38%
0.00465
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22