High severity8.2NVD Advisory· Published Mar 7, 2023· Updated Jun 17, 2026
CVE-2022-42476
CVE-2022-42476
Description
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
Affected products
87.2.0 - 7.2.2, 7.0.0 - 7.0.8+ 4 more
- (no CPE)range: 7.2.0 - 7.2.2, 7.0.0 - 7.0.8
- (no CPE)range: 7.2.0
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.1.0,<=1.1.6
- cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-401nvdVendor Advisory
News mentions
0No linked articles in our index yet.