CVE-2022-42474
Summary
| CVE | CVE-2022-42474 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-13 09:15:00 UTC |
| Updated | 2023-11-07 03:53:00 UTC |
| Description | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Application | Fortinet | Fortiproxy | 7.2.0 | All | All | All |
| Application | Fortinet | Fortiproxy | 7.2.1 | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiswitchmanager | 7.0.0 | All | All | All |
| Application | Fortinet | Fortiswitchmanager | 7.0.1 | All | All | All |
| Application | Fortinet | Fortiswitchmanager | 7.2.0 | All | All | All |
| Application | Fortinet | Fortiswitchmanager | 7.2.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PSIRT Advisories | FortiGuard | MISC | fortiguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 44062 Fortinet FortiOS Path traversal Vulnerability (FG-IR-22-393)