Relative Path Traversal Vulnerability in Fortinet FortiOS and FortiProxy
CVE-2022-41335
8.6HIGH
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 16 February 2023
Summary
A relative path traversal vulnerability exists in Fortinet's FortiOS and FortiProxy, allowing authenticated attackers to exploit crafted HTTP requests. This may enable them to read and write files on the underlying Linux system, potentially compromising critical data and system integrity. Affected versions include FortiOS versions 7.2.0 to 7.2.2, 7.0.0 to 7.0.8, and earlier than 6.4.10, alongside FortiProxy versions 7.2.0 to 7.2.1, 7.0.0 to 7.0.7, and earlier than 2.0.10. Additionally, FortiSwitchManager version 7.2.0 and earlier than 7.0.0 are also impacted.
Affected Version(s)
FortiOS 7.2.0 <= 7.2.2
FortiOS 7.0.0 <= 7.0.8
FortiOS 6.4.0 <= 6.4.11
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved