CVE-2022-22297: Medium severity fortinet fortiweb vulnerability
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versions 6.0, FortiRecorder all versions 2.7 may allow an authenticated user to read arbitrary files via specially crafted command arguments.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22297?
CVE-2022-22297 is a vulnerability in the command line interpreter of FortiWeb versions 6.0.0 through 6.4.1, FortiRecorder Firmware versions 2.7.0 through 6.4.3.
How does CVE-2022-22297 affect FortiWeb?
CVE-2022-22297 affects FortiWeb versions 6.0.0 through 6.4.1, allowing for incomplete filtering of special elements in the command line interpreter.
What is the severity of CVE-2022-22297?
The severity of CVE-2022-22297 is medium, with a severity value of 5.5.
How can I fix CVE-2022-22297?
To fix CVE-2022-22297, it is recommended to update FortiWeb to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-22297?
More information about CVE-2022-22297 can be found at the FortiGuard website: https://fortiguard.com/psirt/FG-IR-21-218