QID 44072
Date Published: 2023-07-03
QID 44072: Fortinet FortiOS Password Ciphertext Exposure Vulnerability (FG-IR-22-455)
A relative path traversal vulnerability in FortiOS administrative interface may allow a privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests.
Affected Versions:
FortiOS 7.2 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow a remote authenticated attacker to execute arbitrary code or commands via specially crafted requests.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-455
Vendor References
- FG-IR-22-455 -
www.fortiguard.com/psirt/FG-IR-22-455
CVEs related to QID 44072
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-455 |
|