Medium severity6.5NVD Advisory· Published Jun 13, 2023· Updated Jun 17, 2026
CVE-2022-42474
CVE-2022-42474
Description
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests.
Affected products
14cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.0.0,<=1.0.7
- cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0 - 7.2.1, 7.0.0 - 7.0.7
- (no CPE)range: 7.2.0
cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiswitchmanager:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiswitchmanager:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiswitchmanager:7.2.1:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0 - 7.2.1, <7.0.1
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-393nvdVendor Advisory
News mentions
0No linked articles in our index yet.