5.5
CVE-2022-22297
- EPSS 0.06%
- Veröffentlicht 07.03.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:46:35
- Quelle psirt@fortinet.com
- Teams Watchlist Login
- Unerledigt Login
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versions 6.0, FortiRecorder all versions 2.7 may allow an authenticated user to read arbitrary files via specially crafted command arguments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortirecorder Firmware Version >= 2.7.0 <= 2.7.7
Fortinet ≫ Fortirecorder Firmware Version >= 6.0.0 <= 6.0.12
Fortinet ≫ Fortirecorder Firmware Version >= 6.4.0 <= 6.4.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.162 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
psirt@fortinet.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-792 Incomplete Filtering of One or More Instances of Special Elements
The product receives data from an upstream component, but does not completely filter one or more instances of special elements before sending it to a downstream component.