CVE-2022-41335: Path Traversal
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-41335?
CVE-2022-41335 is a relative path traversal vulnerability in Fortinet FortiOS, FortiProxy, and FortiSwitchManager.
Which software versions are affected by CVE-2022-41335?
Fortinet FortiOS 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, and versions before 6.4.10; FortiProxy 7.2.0 through 7.2.1, 7.0.0 through 7.0.7, and versions before 2.0.10; FortiSwitchManager 7.2.0 and versions before 7.0.0 are affected by CVE-2022-41335.
What is the severity of CVE-2022-41335?
CVE-2022-41335 has a severity score of 8.1 (high).
How can an authenticated attacker exploit CVE-2022-41335?
An authenticated attacker can exploit CVE-2022-41335 to perform relative path traversal and read sensitive files.
Is there a fix available for CVE-2022-41335?
Yes, Fortinet has released patches to address the vulnerability. It is recommended to update to the latest version of affected software.