VYPR
Medium severity5.3NVD Advisory· Published Mar 7, 2023· Updated Jun 17, 2026

CVE-2022-41329

CVE-2022-41329

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.

Affected products

6
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.8
    • (no CPE)range: 7.2.0 through 7.2.1, 7.0.0 through 7.0.7
    • (no CPE)range: 7.2.0
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.2.3,<=6.2.13
    • (no CPE)range: 7.2.0 through 7.2.3, 7.0.0 through 7.0.9
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.