VYPR
Medium severity6.6NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026

CVE-2022-33871

CVE-2022-33871

Description

A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI execute backup-local rename and execute backup-local show operations.

Affected products

8
  • Fortinet/Fortiweb8 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.6,<6.3.20
    • cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
    • (no CPE)range: <=7.0.1, 6.4.*, <=6.3.19
    • (no CPE)range: 7.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.