QID 43978

Date Published: 2023-02-22

QID 43978: Fortinet FortiOS Authenticated Path Traversal Vulnerability (FG-IR-22-391)

Fortinet FortiOS versions is vulnerable to path traversal vulnerability.

Affected Versions:
FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.12

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of this vulnerability may allow an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-391
    Vendor References

    CVEs related to QID 43978

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-391 URL Logo www.fortiguard.com/psirt/FG-IR-22-391