Vulnerability Details CVE-2022-41335
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 allows an authenticated attacker to read and write files on the underlying Linux system via crafted HTTP requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.0%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-41335
-
cpe:2.3:a:fortinet:fortiproxy:1.1.0
-
cpe:2.3:a:fortinet:fortiproxy:1.1.1
-
cpe:2.3:a:fortinet:fortiproxy:1.1.2
-
cpe:2.3:a:fortinet:fortiproxy:1.1.3
-
cpe:2.3:a:fortinet:fortiproxy:1.1.4
-
cpe:2.3:a:fortinet:fortiproxy:1.1.5
-
cpe:2.3:a:fortinet:fortiproxy:1.1.6
-
cpe:2.3:a:fortinet:fortiproxy:1.2.0
-
cpe:2.3:a:fortinet:fortiproxy:1.2.1
-
cpe:2.3:a:fortinet:fortiproxy:1.2.10
-
cpe:2.3:a:fortinet:fortiproxy:1.2.11
-
cpe:2.3:a:fortinet:fortiproxy:1.2.12
-
cpe:2.3:a:fortinet:fortiproxy:1.2.13
-
cpe:2.3:a:fortinet:fortiproxy:1.2.2
-
cpe:2.3:a:fortinet:fortiproxy:1.2.3
-
cpe:2.3:a:fortinet:fortiproxy:1.2.4
-
cpe:2.3:a:fortinet:fortiproxy:1.2.5
-
cpe:2.3:a:fortinet:fortiproxy:1.2.6
-
cpe:2.3:a:fortinet:fortiproxy:1.2.7
-
cpe:2.3:a:fortinet:fortiproxy:1.2.8
-
cpe:2.3:a:fortinet:fortiproxy:1.2.9
-
cpe:2.3:a:fortinet:fortiproxy:2.0.0
-
cpe:2.3:a:fortinet:fortiproxy:2.0.1
-
cpe:2.3:a:fortinet:fortiproxy:2.0.10
-
cpe:2.3:a:fortinet:fortiproxy:2.0.2
-
cpe:2.3:a:fortinet:fortiproxy:2.0.3
-
cpe:2.3:a:fortinet:fortiproxy:2.0.4
-
cpe:2.3:a:fortinet:fortiproxy:2.0.5
-
cpe:2.3:a:fortinet:fortiproxy:2.0.6
-
cpe:2.3:a:fortinet:fortiproxy:2.0.7
-
cpe:2.3:a:fortinet:fortiproxy:2.0.8
-
cpe:2.3:a:fortinet:fortiproxy:2.0.9
-
cpe:2.3:a:fortinet:fortiproxy:7.0.0
-
cpe:2.3:a:fortinet:fortiproxy:7.0.1
-
cpe:2.3:a:fortinet:fortiproxy:7.0.2
-
cpe:2.3:a:fortinet:fortiproxy:7.0.3
-
cpe:2.3:a:fortinet:fortiproxy:7.0.4
-
cpe:2.3:a:fortinet:fortiproxy:7.0.5
-
cpe:2.3:a:fortinet:fortiproxy:7.0.6
-
cpe:2.3:a:fortinet:fortiproxy:7.0.7
-
cpe:2.3:a:fortinet:fortiproxy:7.2.0
-
cpe:2.3:a:fortinet:fortiproxy:7.2.1
-
cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0
-
cpe:2.3:a:fortinet:fortiswitchmanager:7.2.0
-
cpe:2.3:o:fortinet:fortios:6.2.0
-
cpe:2.3:o:fortinet:fortios:6.2.1
-
cpe:2.3:o:fortinet:fortios:6.2.10
-
cpe:2.3:o:fortinet:fortios:6.2.11
-
cpe:2.3:o:fortinet:fortios:6.2.12
-
cpe:2.3:o:fortinet:fortios:6.2.2
-
cpe:2.3:o:fortinet:fortios:6.2.3
-
cpe:2.3:o:fortinet:fortios:6.2.4
-
cpe:2.3:o:fortinet:fortios:6.2.5
-
cpe:2.3:o:fortinet:fortios:6.2.6
-
cpe:2.3:o:fortinet:fortios:6.2.7
-
cpe:2.3:o:fortinet:fortios:6.2.8
-
cpe:2.3:o:fortinet:fortios:6.2.9
-
cpe:2.3:o:fortinet:fortios:6.4.0
-
cpe:2.3:o:fortinet:fortios:6.4.1
-
cpe:2.3:o:fortinet:fortios:6.4.10
-
cpe:2.3:o:fortinet:fortios:6.4.2
-
cpe:2.3:o:fortinet:fortios:6.4.3
-
cpe:2.3:o:fortinet:fortios:6.4.4
-
cpe:2.3:o:fortinet:fortios:6.4.5
-
cpe:2.3:o:fortinet:fortios:6.4.6
-
cpe:2.3:o:fortinet:fortios:6.4.7
-
cpe:2.3:o:fortinet:fortios:6.4.8
-
cpe:2.3:o:fortinet:fortios:6.4.9
-
cpe:2.3:o:fortinet:fortios:7.0.0
-
cpe:2.3:o:fortinet:fortios:7.0.1
-
cpe:2.3:o:fortinet:fortios:7.0.2
-
cpe:2.3:o:fortinet:fortios:7.0.3
-
cpe:2.3:o:fortinet:fortios:7.0.4
-
cpe:2.3:o:fortinet:fortios:7.0.5
-
cpe:2.3:o:fortinet:fortios:7.0.6
-
cpe:2.3:o:fortinet:fortios:7.0.7
-
cpe:2.3:o:fortinet:fortios:7.0.8
-
cpe:2.3:o:fortinet:fortios:7.2.0
-
cpe:2.3:o:fortinet:fortios:7.2.1
-
cpe:2.3:o:fortinet:fortios:7.2.2