Impact
The vulnerability is a path‑traversal flaw that allows an unauthenticated attacker to write arbitrary files to the underlying operating system via crafted HTTP or HTTPS requests. This capability can lead to full system compromise, enabling the planting of malicious binaries or configuration files that compromise confidentiality, integrity, and availability of the mail services. The flaw is rated CVSS 9.8, reflecting a critical severity and the high potential for exploitation.
Affected Systems
Fortinet FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 are affected. No other products are listed as impacted.
Risk and Exploitability
Because authentication is not required and the attack vector is standard HTTP/HTTPS traffic, an adversary can readily attempt to write to privileged locations. The CVSS score of 9.8 indicates the possibility of complete system takeover. EPSS is currently unavailable and the vulnerability is not catalogued in CISA KEV, but the high severity and lack of authentication requirements make it a serious exposure for any exposed FortiMail installation.
OpenCVE Enrichment