CVE-2022-42470: Path Traversal
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-42470?
CVE-2022-42470 is a relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9, and 6.0.0 - 6.0.10 that allows an attacker to execute unauthorized code or commands.
How does CVE-2022-42470 affect Fortinet FortiClient on Windows?
CVE-2022-42470 affects Fortinet FortiClient (Windows) versions 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9, and 6.0.0 - 6.0.10.
What is the severity of CVE-2022-42470?
CVE-2022-42470 has a severity rating of 7.8 (high).
How can an attacker exploit CVE-2022-42470?
An attacker can exploit CVE-2022-42470 by sending a crafted request to a specific named pipe.
Is there a fix available for CVE-2022-42470?
Yes, Fortinet has provided a fix for CVE-2022-42470. It is recommended to update to the latest version of Fortinet FortiClient (Windows) to mitigate this vulnerability.