← Back to CVE List
CVE-2022-41328NVD
Vulnerability Summary
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.
CVSS v3.1 Base Metrics — Score 6.5 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Fortinet FortiOS >= 7.2.0 and <= 7.2.3
- Fortinet FortiOS >= 7.0.0 and <= 7.0.9
- Fortinet FortiOS >= 6.4.0 and <= 6.4.11
- Fortinet FortiOS >= 6.2.0 and <= 6.2.13
- Fortinet FortiOS >= 6.0.0 and <= 6.0.16
- Fortinet FortiOS 7.2.3
- Fortinet FortiOS 7.0.9
- Fortinet FortiOS 6.4.11
- Fortinet FortiOS 6.2.13
- Fortinet FortiOS 6.0.16