Lucene search

K
nvd[email protected]NVD:CVE-2022-42474
HistoryJun 13, 2023 - 9:15 a.m.

CVE-2022-42474

2023-06-1309:15:15
CWE-23
CWE-22
web.nvd.nist.gov
3
fortinet
relative path traversal
filesystem deletion

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

30.1%

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests.

Affected configurations

Nvd
Node
fortinetfortiproxyRange1.0.01.0.7
OR
fortinetfortiproxyRange1.1.01.1.6
OR
fortinetfortiproxyRange1.2.01.2.13
OR
fortinetfortiproxyRange2.0.02.0.11
OR
fortinetfortiproxyRange7.0.07.0.7
OR
fortinetfortiproxyMatch7.2.0
OR
fortinetfortiproxyMatch7.2.1
OR
fortinetfortiswitchmanagerMatch7.0.0
OR
fortinetfortiswitchmanagerMatch7.0.1
OR
fortinetfortiswitchmanagerMatch7.2.0
OR
fortinetfortiswitchmanagerMatch7.2.1
OR
fortinetfortiosRange6.2.06.2.15
OR
fortinetfortiosRange6.4.06.4.12
OR
fortinetfortiosRange7.0.07.0.9
OR
fortinetfortiosRange7.2.07.2.3
VendorProductVersionCPE
fortinetfortiproxy*cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
fortinetfortiproxy7.2.0cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
fortinetfortiproxy7.2.1cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
fortinetfortiswitchmanager7.0.0cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0:*:*:*:*:*:*:*
fortinetfortiswitchmanager7.0.1cpe:2.3:a:fortinet:fortiswitchmanager:7.0.1:*:*:*:*:*:*:*
fortinetfortiswitchmanager7.2.0cpe:2.3:a:fortinet:fortiswitchmanager:7.2.0:*:*:*:*:*:*:*
fortinetfortiswitchmanager7.2.1cpe:2.3:a:fortinet:fortiswitchmanager:7.2.1:*:*:*:*:*:*:*
fortinetfortios*cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

30.1%

Related for NVD:CVE-2022-42474