CVE-2022-38372: Medium severity fortinet fortitester vulnerability
A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38372?
CVE-2022-38372 is a hidden functionality vulnerability in FortiTester CLI versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0.
How does CVE-2022-38372 impact the device?
CVE-2022-38372 may allow a local, privileged user to obtain a root shell on the FortiTester device via an undocumented command.
What is the severity of CVE-2022-38372?
CVE-2022-38372 has a severity rating of medium with a CVSS score of 6.7.
Which versions of FortiTester CLI are affected?
FortiTester CLI versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0 are affected.
How can I fix CVE-2022-38372?
To fix CVE-2022-38372, it is recommended to update FortiTester CLI to a version that is not affected by the vulnerability.