CVE-2022-42476
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
07/03/2023
Last modified:
07/11/2023
Description
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | 1.1.0 (including) | 1.1.6 (including) |
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | 1.2.0 (including) | 1.2.13 (including) |
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.0.11 (including) |
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.0.7 (including) |
cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 6.2.0 (including) | 6.2.12 (including) |
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 6.4.0 (including) | 6.4.11 (including) |
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.0.8 (including) |
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 7.2.0 (including) | 7.2.3 (including) |
To consult the complete list of CPE names with products and versions, see this page