CVE-2022-30302: Path Traversal
Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlying filesystem via specially crafted web requests.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of the multiple relative path traversal vulnerabilities in FortiDeceptor?
The vulnerability ID is CVE-2022-30302.
What is the severity of CVE-2022-30302?
The severity of CVE-2022-30302 is high with a CVSS score of 8.1.
Which software versions of FortiDeceptor are affected by CVE-2022-30302?
FortiDeceptor management interface versions 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 are affected.
How can a remote and authenticated attacker exploit CVE-2022-30302?
A remote and authenticated attacker can exploit CVE-2022-30302 by crafting specially crafted web requests to retrieve and delete arbitrary files from the underlying filesystem.
Is there a fix available for CVE-2022-30302?
Yes, a fix for CVE-2022-30302 is available. It is recommended to update to a patched version of FortiDeceptor management interface.