CVE-2022-41335
published 2023-02-16CVE-2022-41335: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version…
PriorityP180high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.93%
56.3th percentile
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 6.2.0 – 6.2.12 | — |
| fortinet | fortios | 6.4.0 – 6.4.10 | — |
| fortinet | fortios | 7.0.0 – 7.0.8 | — |
| fortinet | fortios | 7.2.0 – 7.2.2 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 1.0.0 < 1.0.* | 1.0.* |
| fortinet | fortiproxy | >= 1.1.0 < 1.1.* | 1.1.* |
| fortinet | fortiproxy | 1.1.0 – 1.1.6 | — |
| fortinet | fortiproxy | >= 1.2.0 < 1.2.* | 1.2.* |
| fortinet | fortiproxy | 1.2.0 – 1.2.13 | — |
| fortinet | fortiproxy | 2.0.0 – 2.0.10 | — |
| fortinet | fortiproxy | 7.0.0 – 7.0.7 | — |
| fortinet | fortiproxy | 7.2.0 – 7.2.1 | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploited via crafted HTTP requests to the administrative interface, targeting a relative path traversal (CWE-23) to read/write arbitrary files on the underlying Linux system. Monitor administrative interface HTTP traffic for path traversal patterns (e.g., '../' sequences) in request URIs. ↗
- ·Exploitation requires authentication; ensure administrative interface access is restricted to trusted IPs and monitor for anomalous authenticated sessions on FortiOS, FortiProxy, and FortiSwitchManager administrative interfaces. ↗
- ·Affected versions span FortiOS 7.2.0–7.2.2, 7.0.0–7.0.8, and before 6.4.10; FortiProxy 7.2.0–7.2.1, 7.0.0–7.0.7, and before 2.0.10; FortiSwitchManager 7.2.0 and before 7.0.0. Ensure patching covers all three product lines. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Arbitrary read/write vulnerability in administrative interface
vendor_fortinet·2023-02-16·CVSS 8.8
CVE-2022-41335 [HIGH] CWE-22 Arbitrary read/write vulnerability in administrative interface
FG-IR-22-391: Arbitrary read/write vulnerability in administrative interface
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.
CVEs: CVE-2022-41335
CWEs: CWE-22, CWE-23
CVSS: 8.8 (high)
Affected products: FortiOS, FortiProxy, FortiSwitchManager, FortiSwitchmanager, Fortinet
GHSA
GHSA-gjq5-3p29-m546: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7
ghsa_unreviewed·2023-02-16
CVE-2022-41335 [HIGH] CWE-22 GHSA-gjq5-3p29-m546: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.
VulnCheck
Fortinet fortiswitchmanager Relative Path Traversal
vulncheck·2022·CVSS 8.8
CVE-2022-41335 [HIGH] Fortinet fortiswitchmanager Relative Path Traversal
Fortinet fortiswitchmanager Relative Path Traversal
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.
Affected: Fortinet fortiswitchmanager
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.cybereason.com/hubfs/Consulting/TTP%20Briefing/Cybereason_TTP_Briefing_Jan-May-2025.pdf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published
Exploited in the wild