Vulnerability Details CVE-2025-60024
Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-60024
-
cpe:2.3:a:fortinet:fortivoice:7.0.0
-
cpe:2.3:a:fortinet:fortivoice:7.0.1
-
cpe:2.3:a:fortinet:fortivoice:7.0.2
-
cpe:2.3:a:fortinet:fortivoice:7.0.3
-
cpe:2.3:a:fortinet:fortivoice:7.0.4
-
cpe:2.3:a:fortinet:fortivoice:7.0.5
-
cpe:2.3:a:fortinet:fortivoice:7.0.6
-
cpe:2.3:a:fortinet:fortivoice:7.0.7
-
cpe:2.3:a:fortinet:fortivoice:7.2.0
-
cpe:2.3:a:fortinet:fortivoice:7.2.1
-
cpe:2.3:a:fortinet:fortivoice:7.2.2