CVE-2022-42476Relative Path Traversal in Fortinet Fortios

Severity
8.2HIGHNVD
EPSS
0.1%
top 76.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7

Description

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages4 packages

CVEListV5fortinet/fortios7.2.07.2.3+3
NVDfortinet/fortios6.2.06.2.12+3
CVEListV5fortinet/fortiproxy7.2.07.2.1+4
NVDfortinet/fortiproxy1.1.01.1.6+5

🔴Vulnerability Details

2
GHSA
GHSA-w4p8-qcm4-827w: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 72023-03-07
CVEList
CVE-2022-42476: A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 72023-03-07

📋Vendor Advisories

1
Fortinet
FortiOS / FortiProxy - Path traversal vulnerability allows VDOM escaping2023-03-07
CVE-2022-42476 — Relative Path Traversal in Fortinet | cvebase