CVE-2022-23447
published 2023-07-11CVE-2022-23447: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through…
PriorityP354high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.80%
52.3th percentile
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | 3.2.1 – 3.2.3 | — |
| fortinet | fortiextender | 3.3.0 – 3.3.2 | — |
| fortinet | fortiextender | 4.0.0 – 4.0.2 | — |
| fortinet | fortiextender | 4.1.1 – 4.1.8 | — |
| fortinet | fortiextender | 4.2.0 – 4.2.4 | — |
| fortinet | fortiextender | 7.0.0 – 7.0.3 | — |
| fortinet | fortiextender_firmware | — | — |
| fortinet | fortiextender_firmware | >= 3.2.1 < 3.2.4 | 3.2.4 |
| fortinet | fortiextender_firmware | >= 3.3.0 < 3.3.3 | 3.3.3 |
| fortinet | fortiextender_firmware | >= 4.0.0 < 4.0.3 | 4.0.3 |
| fortinet | fortiextender_firmware | >= 4.1.1 < 4.1.9 | 4.1.9 |
| fortinet | fortiextender_firmware | >= 4.2.0 < 4.2.5 | 4.2.5 |
| fortinet | fortiextender_firmware | >= 7.0.0 < 7.0.4 | 7.0.4 |
| fortinet | fortiextenderfirmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vx64-9phg-mmpv: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7
ghsa_unreviewed·2023-07-11
CVE-2022-23447 [HIGH] CWE-22 GHSA-vx64-9phg-mmpv: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Fortinet
Path Traversal vulnerability
vendor_fortinet·2023-07-11·CVSS 7.5
CVE-2022-23447 [HIGH] CWE-22 Path Traversal vulnerability
FG-IR-22-039: Path Traversal vulnerability
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
CVEs: CVE-2022-23447
CWEs: CWE-22
CVSS: 7.5 (high)
Affected products: FortiExtender, FortiExtenderfirmware
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published