CVE-2022-30301: Relative path traversal vulnerability in CLI
A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to delete and access unauthorized files and data via specifically crafted CLI commands.
Other sources
A path traversal vulnerability [CWE-22] in FortiAP-U CLI may allow an admin user to delete and access unauthorized files and data via specifically crafted CLI commands.
— FortiGuard
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-30301?
CVE-2022-30301 is a path traversal vulnerability in FortiAP-U CLI versions 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, and 5.4.0 through 5.4.6.
How does CVE-2022-30301 affect FortiAP-U CLI?
CVE-2022-30301 allows an admin user to delete and access unauthorized files and data in FortiAP-U CLI through specifically crafted CLI commands.
What is the severity of CVE-2022-30301?
The severity of CVE-2022-30301 is high, with a CVSS score of 6.7.
Which versions of FortiAP-U CLI are affected by CVE-2022-30301?
FortiAP-U CLI versions 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, and 5.4.0 through 5.4.6 are affected by CVE-2022-30301.
How can I fix the CVE-2022-30301 vulnerability?
To fix the CVE-2022-30301 vulnerability, it is recommended to update FortiAP-U CLI to a version that is not affected. Please refer to the vendor's website for the latest updates and patches.