QID 43992
Date Published: 2023-03-15
QID 43992: FortiOS Path Traversal Vulnerability (FG-IR-22-369)
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in FortiOS may allow a privileged attacker to read and write arbitrary files via crafted CLI commands.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable versions of FortiOS may allow a privileged attacker to read and write arbitrary files via crafted CLI commands.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-369
Vendor References
- FG-IR-22-369 -
www.fortiguard.com/psirt/FG-IR-22-369
CVEs related to QID 43992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-369 |
|