Relative Path Traversal Vulnerability in Fortinet FortiOS and FortiProxy
CVE-2022-41335
8.6HIGH
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 16 February 2023
What is CVE-2022-41335?
A relative path traversal vulnerability exists in Fortinet's FortiOS and FortiProxy, allowing authenticated attackers to exploit crafted HTTP requests. This may enable them to read and write files on the underlying Linux system, potentially compromising critical data and system integrity. Affected versions include FortiOS versions 7.2.0 to 7.2.2, 7.0.0 to 7.0.8, and earlier than 6.4.10, alongside FortiProxy versions 7.2.0 to 7.2.1, 7.0.0 to 7.0.7, and earlier than 2.0.10. Additionally, FortiSwitchManager version 7.2.0 and earlier than 7.0.0 are also impacted.
Affected Version(s)
FortiOS 7.2.0 <= 7.2.2
FortiOS 7.0.0 <= 7.0.8
FortiOS 6.4.0 <= 6.4.11