CVE-2022-42476: Path Traversal
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-42476?
CVE-2022-42476 is a relative path traversal vulnerability in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, and before 6.4.11, as well as in FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8.
How severe is CVE-2022-42476?
CVE-2022-42476 has a severity rating of 8.2, which is considered high.
How does CVE-2022-42476 affect Fortinet FortiOS?
CVE-2022-42476 affects Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, and before 6.4.11.
How does CVE-2022-42476 affect FortiProxy?
CVE-2022-42476 affects FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8.
How can I mitigate the risk of CVE-2022-42476?
To mitigate the risk of CVE-2022-42476, it is recommended to update Fortinet FortiOS to version 6.4.11, 7.0.8, or 7.2.3, and FortiProxy to version 7.0.8 or 7.2.3.