CVE-2022-41328
Description
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.
Summary dbcve.org
A path traversal vulnerability (CWE-22) in FortiOS CLI allows a privileged attacker to escape restricted directories and read/write arbitrary files on the underlying Linux filesystem using crafted CLI commands. The vulnerability affects FortiOS versions 7.2.0-7.2.3, 7.0.0-7.0.9, and versions before 6.4.11.
Mitigation
Upgrade FortiOS to version 7.2.4, 7.0.10, 6.4.11 or later. Additionally, restrict administrative access to trusted personnel only and monitor CLI command execution for suspicious activity.