A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to delete and access unauthorized files and data via specifically crafted CLI commands.
2022-07-19T14:15:08.770
2024-11-21T07:02:31.860
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiap-u | ≤ 6.0.4 | Yes |
Application | fortinet | fortiap-u | ≤ 6.2.3 | Yes |
Application | fortinet | fortiap-u | 5.4.0 | Yes |
Application | fortinet | fortiap-u | 5.4.3 | Yes |
Application | fortinet | fortiap-u | 5.4.4 | Yes |
Application | fortinet | fortiap-u | 5.4.5 | Yes |
Application | fortinet | fortiap-u | 5.4.6 | Yes |