HIGH

CVE-2022-41328

Fortinet Fortios 2023-03-07 CVSS v3.1
CVSS
7.1
KEV

Description

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.

Summary dbcve.org

A path traversal vulnerability (CWE-22) in FortiOS CLI allows a privileged attacker to escape restricted directories and read/write arbitrary files on the underlying Linux filesystem using crafted CLI commands. The vulnerability affects FortiOS versions 7.2.0-7.2.3, 7.0.0-7.0.9, and versions before 6.4.11.

Mitigation

Upgrade FortiOS to version 7.2.4, 7.0.10, 6.4.11 or later. Additionally, restrict administrative access to trusted personnel only and monitor CLI command execution for suspicious activity.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

10.68%
Probability of exploitation in next 30 days
95.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE