QID 44040

Date Published: 2023-05-31

QID 44040: Fortinet FortiOS Authenticated Path Traversal Vulnerability (FG-IR-22-391) (Unauthenticated Check)

Fortinet FortiOS versions is vulnerable to path traversal vulnerability.

Affected Versions:
FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.12

QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP or HTTPS GET requests.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-363
    Vendor References

    CVEs related to QID 44040

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-363 URL Logo www.fortiguard.com/psirt/FG-IR-22-363