HIGH🇵🇱 Wersja polska

CVE-2022-23447

CVSS 7.5v3.1pub. 2023-07-11upd. 2024-11-21

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Fortinet Fortiextender

    HW
    Fortinet
    all versions
  • Fortinet Fortiextender Firmware

    OS
    Fortinet
    5.3.24.0.0 – 4.0.3 (excl.)4.1.1 – 4.1.9 (excl.)3.2.1 – 3.2.4 (excl.)7.0.0 – 7.0.4 (excl.)4.2.0 – 4.2.5 (excl.)3.3.0 – 3.3.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-64153HIGH7.2same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...

CVE-2024-23663HIGH8.8same product

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0...

CVE-2022-27489HIGH7.2same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...

CVE-2021-41016HIGH7.8same product

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtende...

CVE-2025-46775MEDIUM5.5same product

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1...