Relative Path Traversal Vulnerability in Fortinet FortiOS and FortiProxy Products
CVE-2022-42474
6.2MEDIUM
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 13 June 2023
Summary
A relative path traversal vulnerability exists in multiple Fortinet products, including FortiOS, FortiProxy, and FortiSwitchManager. This issue allows an authenticated attacker with privileged access to send specific crafted HTTP requests, potentially leading to the unauthorized deletion of arbitrary directories from the system's filesystem, compromising the integrity and availability of the affected systems.
Affected Version(s)
FortiOS 7.2.0 <= 7.2.3
FortiOS 7.0.0 <= 7.0.9
FortiOS 6.4.0 <= 6.4.12
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved