CVE-2022-23447: Path Traversal
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23447?
CVE-2022-23447 is classified as a high severity vulnerability due to its potential for path traversal exploitation.
What systems are affected by CVE-2022-23447?
CVE-2022-23447 affects FortiExtender management interface versions 3.2.1 to 3.2.4, 4.0.0 to 4.0.3, 4.1.1 to 4.1.9, 4.2.0 to 4.2.5, and 7.0.0 to 7.0.4.
How do I fix CVE-2022-23447?
To remediate CVE-2022-23447, upgrade the FortiExtender firmware to the latest version available beyond the affected versions.
What is a path traversal vulnerability like CVE-2022-23447?
A path traversal vulnerability, such as CVE-2022-23447, allows an attacker to access files and directories outside of the intended directory structure.
Can CVE-2022-23447 be exploited remotely?
Yes, CVE-2022-23447 can potentially be exploited remotely if an attacker interacts with the vulnerable FortiExtender management interface.