CVE-2022-22299: High severity fortinet fortiadc vulnerability
A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22299?
CVE-2022-22299 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2022-22299?
To fix CVE-2022-22299, upgrade to FortiADC versions 6.0.5 or later, 6.1.6 or later, 6.2.2 or later, or the latest versions of FortiProxy and FortiMail.
What software is affected by CVE-2022-22299?
CVE-2022-22299 affects multiple versions of FortiADC, FortiProxy, and FortiMail software.
What types of attacks can exploit CVE-2022-22299?
CVE-2022-22299 can be exploited through format string vulnerabilities, which can lead to unauthorized access or system crashes.
Is there a workaround for CVE-2022-22299?
Currently, the only reliable workaround for CVE-2022-22299 is to apply the appropriate updates to the affected software.