Path traversal in FortiOS - CVE-2022-41328
Published: March 9, 2023 / Updated: March 14, 2023
Vulnerability identifier: #VU73199
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41328
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing certain CLI command. A local user can read and write arbitrary files on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
FortiOS
RUGGEDCOM APE1808
RUGGEDCOM APE1808
How to mitigate CVE-2022-41328
Install update from vendor's website.
FortiOS - addressed in versions 6.4.12, 7.0.10, 7.2.4