QID 43994
Date Published: 2023-03-21
QID 43994: FortiOS Path Traversal Vulnerability (FG-IR-22-401)
A relative path traversal vulnerability [CWE-23] in FortiOS and FortiProxy may allow privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.11
FortiOS version 6.2.0 through 6.2.12
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable OS may allow privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-401
Vendor References
- FG-IR-22-401 -
www.fortiguard.com/psirt/FG-IR-22-401
CVEs related to QID 43994
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-401 |
|