CVE-2022-23447
11.07.2023, 17:15
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrievearbitrary files from the underlying filesystem via specially crafted web requests.
Vendor | Product | Version |
---|---|---|
fortinet | fortiextender_firmware | 3.2.1 ≤ 𝑥 < 3.2.4 |
fortinet | fortiextender_firmware | 3.3.0 ≤ 𝑥 < 3.3.3 |
fortinet | fortiextender_firmware | 4.0.0 ≤ 𝑥 < 4.0.3 |
fortinet | fortiextender_firmware | 4.1.1 ≤ 𝑥 < 4.1.9 |
fortinet | fortiextender_firmware | 4.2.0 ≤ 𝑥 < 4.2.5 |
fortinet | fortiextender_firmware | 7.0.0 ≤ 𝑥 < 7.0.4 |
fortinet | fortiextender_firmware | 5.3.2 |
𝑥
= Vulnerable software versions