Impact
The vulnerability is a path traversal flaw (CWE‑22) that allows an attacker to read or write files outside the intended directory, potentially enabling execution of arbitrary code or commands. This flaw can compromise the confidentiality, integrity, and availability of the affected devices. The description states that an attacker may be able to execute unauthorized code or commands, but the specific attack vector is not detailed, so it is inferred that the vector likely involves sending specially crafted HTTP requests to the device’s management interface where the path is not properly validated.
Affected Systems
The flaw impacts multiple Fortinet products. FortiOS versions 6.4 through 7.6.6, including all 7.0, 7.2, 7.4, and 7.6 branches, are affected. FortiPAM releases from 1.0 up to 1.8.0, including the 1.5, 1.6, 1.7, and 1.8 branches, are vulnerable. FortiProxy versions 7.0 through 7.6.5, encompassing the 7.2, 7.4, and 7.6 branches, are also impacted. The advisory also references FortiSwitchManager (7.2.8 or above) and FortiSASE, with FortiSASE customers already on a patched version where no additional action is required.
Risk and Exploitability
The CVSS score of 5.0 marks the vulnerability as medium, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no known active exploitation. Successful exploitation would require network access to the device’s management interface and the ability to craft a request that bypasses path restrictions, potentially allowing remote code execution or command injection.
OpenCVE Enrichment