CVE-2022-41335
Summary
| CVE | CVE-2022-41335 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-16 19:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43978 Fortinet FortiOS Authenticated Path Traversal Vulnerability (FG-IR-22-391)
- 44040 Fortinet FortiOS Authenticated Path Traversal Vulnerability (FG-IR-22-391) (Unauthenticated Check)