Junglewise Threat Intelligence

CVE-2022-41328: Fortinet FortiOS Path Traversal Vulnerability

CVE-2022-41328 · Severity: critical · CVSS 7.1 · Exploited in the wild · Published 2023-03-14

Technologies: Fortinet FortiProxy SSL-VPN, Fortinet FortiOS, Fortinet FortiADC, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A path traversal vulnerability in Fortinet FortiOS allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands. This flaw stems from improper limitation of a pathname to a restricted directory.

Affected products

  • Fortinet FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.9, 6.4.0 through 6.4.11, 6.2.0 through 6.2.13, 6.0.0 through 6.0.16

Timeline

  • 2023-03-07: disclosed
  • 2023-03-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-14: advisory: NVD publication date

Related threats