High severity7.5NVD Advisory· Published Jul 11, 2023· Updated Jun 17, 2026
CVE-2022-23447
CVE-2022-23447
Description
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected products
4cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:*range: >=3.2.1,<3.2.4
- cpe:2.3:o:fortinet:fortiextender_firmware:5.3.2:*:*:*:*:*:*:*
7.0.0-7.0.3, 4.2.0-4.2.4, 4.1.1-4.1.8, 4.0.0-4.0.2, 3.3.0-3.3.2, 3.2.1-3.2.3, 5.3+ 1 more
- (no CPE)range: 7.0.0-7.0.3, 4.2.0-4.2.4, 4.1.1-4.1.8, 4.0.0-4.0.2, 3.3.0-3.3.2, 3.2.1-3.2.3, 5.3
- (no CPE)range: 7.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-039nvdVendor Advisory
News mentions
0No linked articles in our index yet.