cbcvebase.
CVE-2022-22299
published 2022-08-05

CVE-2022-22299: A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.

Affected

24 ranges
VendorProductVersion rangeFixed in
fortinetfortiadc
fortinetfortiadc
fortinetfortiadc
fortinetfortiadc6.0.0 – 6.0.4
fortinetfortiadc6.1.0 – 6.1.6
fortinetfortimail
fortinetfortimail6.4.0 – 6.4.5
fortinetfortimail7.0.0 – 7.0.2
fortinetfortios
fortinetfortios5.0.0 – 5.0.14
fortinetfortios5.2.0 – 5.2.15
fortinetfortios5.4.0 – 5.4.13
fortinetfortios5.6.0 – 5.6.14
fortinetfortios6.0.0 – 6.0.14
fortinetfortios6.2.0 – 6.2.10
fortinetfortios>= 6.4.0 < 6.4.86.4.8
fortinetfortios>= 7.0.0 < 7.0.27.0.2
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy1.0.0 – 1.0.7
fortinetfortiproxy1.1.0 – 1.1.6
fortinetfortiproxy1.2.0 – 1.2.13
fortinetfortiproxy2.0.0 – 2.0.7