A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their privileges to super admin of the box via crafted CLI requests.
2023-03-07T17:15:12.303
2024-11-21T07:25:02.870
Modified
CVSSv3.1: 8.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | ≤ 1.1.6 | Yes |
Application | fortinet | fortiproxy | ≤ 1.2.13 | Yes |
Application | fortinet | fortiproxy | ≤ 2.0.11 | Yes |
Application | fortinet | fortiproxy | ≤ 7.0.7 | Yes |
Application | fortinet | fortiproxy | 7.2.0 | Yes |
Application | fortinet | fortiproxy | 7.2.1 | Yes |
Operating System | fortinet | fortios | ≤ 6.2.12 | Yes |
Operating System | fortinet | fortios | ≤ 6.4.11 | Yes |
Operating System | fortinet | fortios | ≤ 7.0.8 | Yes |
Operating System | fortinet | fortios | ≤ 7.2.3 | Yes |