QID 44062

Date Published: 2023-06-27

QID 44062: Fortinet FortiOS Path traversal Vulnerability (FG-IR-22-393)

A relative path traversal vulnerability in FortiOS administrative interface may allow a privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests.

Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.12
FortiOS 6.2 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Note: Due to banner based detection this QID is kept as practice.

Successful exploitation of the vulnerability may allow a privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests.

  • CVSS V3 rated as Low - 2.7 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-393
    Vendor References

    CVEs related to QID 44062

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-393 URL Logo www.fortiguard.com/psirt/FG-IR-22-393