Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27443 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versions 6.0, FortiRecorder all versions 2.7 may allow an authenticated user to read arbitrary files via specially crafted command arguments. |
Solution
Upgrade to FortiWeb version 7.0.0 or above, Upgrade to FortiWeb version 6.4.2 or above. Upgrade to FortiWeb version 6.3.18 or above. Upgrade to FortiRecorder version 7.0.0 or above Upgrade to FortiRecorder version 6.4.4 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-218 |
|
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:48:26.477Z
Reserved: 2022-01-03T09:39:36.527Z
Link: CVE-2022-22297
Updated: 2024-08-03T03:07:50.182Z
Status : Modified
Published: 2023-03-07T17:15:11.707
Modified: 2024-11-21T06:46:35.323
Link: CVE-2022-22297
No data.
OpenCVE Enrichment
No data.
EUVD