{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2022-23447","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2022-01-19T07:38:03.514Z","datePublished":"2023-07-11T16:52:42.353Z","dateUpdated":"2024-10-23T14:25:28.182Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiExtender","defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"7.0.0","lessThanOrEqual":"7.0.3","status":"affected"},{"version":"5.3.2","status":"affected"},{"versionType":"semver","version":"4.2.0","lessThanOrEqual":"4.2.4","status":"affected"},{"versionType":"semver","version":"4.1.1","lessThanOrEqual":"4.1.8","status":"affected"},{"versionType":"semver","version":"4.0.0","lessThanOrEqual":"4.0.2","status":"affected"},{"versionType":"semver","version":"3.3.0","lessThanOrEqual":"3.3.2","status":"affected"},{"versionType":"semver","version":"3.2.1","lessThanOrEqual":"3.2.3","status":"affected"}]}],"descriptions":[{"lang":"en","value":"An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface  7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2023-07-11T16:52:42.353Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-22","description":"Information disclosure","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C"}}],"solutions":[{"lang":"en","value":"Please upgrade to FortiExtender version 7.2.0 or above Please upgrade to FortiExtender version 7.0.4 or above Please upgrade to FortiExtender version 4.2.5 or above Please upgrade to FortiExtender version 4.1.9 or above Please upgrade to FortiExtender version 4.0.3 or above Please upgrade to FortiExtender version 3.3.3 or above Please upgrade to FortiExtender version 3.2.4 or above "}],"references":[{"name":"https://fortiguard.com/psirt/FG-IR-22-039","url":"https://fortiguard.com/psirt/FG-IR-22-039"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T03:43:46.110Z"},"title":"CVE Program Container","references":[{"name":"https://fortiguard.com/psirt/FG-IR-22-039","url":"https://fortiguard.com/psirt/FG-IR-22-039","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-10-23T14:15:33.419696Z","id":"CVE-2022-23447","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-23T14:25:28.182Z"}}]}}