CVE-2022-41328 is a critical path traversal vulnerability (CWE-22) affecting Fortinet FortiOS versions 7.2.0-7.2.3, 7.0.0-7.0.9, and before 6.4.11. A privileged attacker can exploit this flaw via crafted CLI commands to read and write files on the underlying Linux system. With a CVSS score of 7.1 (High), this vulnerability allows for high confidentiality and integrity impacts with low attack complexity, requiring local access and low privileges. This CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community attention with 14 mentions and 13 media articles, despite no public exploit intelligence like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.0.16CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.14CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 6.4.12CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.10CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.2.0, < 7.2.4CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.