Executive brief
A path traversal vulnerability in Fortinet FortiOS allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands. This flaw stems from improper limitation of a pathname to a restricted directory.
Affected products
- Fortinet FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.9, 6.4.0 through 6.4.11, 6.2.0 through 6.2.13, 6.0.0 through 6.0.16
Timeline
- 2023-03-07: disclosed
- 2023-03-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-03-14: advisory: NVD publication date