VYPR
Medium severity6.5NVD Advisory· Published Jun 13, 2023· Updated Jun 17, 2026

CVE-2022-42474

CVE-2022-42474

Description

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete arbitrary directories from the filesystem through crafted HTTP requests.

Affected products

14
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.0.0,<=1.0.7
    • cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
    • (no CPE)range: 7.2.0 - 7.2.1, 7.0.0 - 7.0.7
    • (no CPE)range: 7.2.0
  • cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiswitchmanager:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiswitchmanager:7.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiswitchmanager:7.2.1:*:*:*:*:*:*:*
    • (no CPE)range: 7.2.0 - 7.2.1, <7.0.1
    • (no CPE)range: 7.2.0
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.2.0,<=6.2.15
    • (no CPE)range: 7.2.0 - 7.2.3, 7.0.0 - 7.0.9, <6.4.12
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.