CVE-2025-22859

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
13/05/2025
Last modified:
16/07/2025

Description

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.3 (excluding)
cpe:2.3:a:fortinet:forticlientems_cloud:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.3 (excluding)


References to Advisories, Solutions, and Tools