Medium severity6.6NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026
CVE-2022-33871
CVE-2022-33871
Description
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a privileged attacker to execute arbitrary code or commands via specifically crafted CLI execute backup-local rename and execute backup-local show operations.
Affected products
8cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.6,<6.3.20
- cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
- (no CPE)range: <=7.0.1, 6.4.*, <=6.3.19
- (no CPE)range: 7.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-164nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.