CVE-2022-23447: Fortinet Fortiextender Firmware
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and remote attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected products
- Fortinet Fortiextender Firmware: from 3.2.1, before 3.2.4 (fixed in 3.2.4); from 3.3.0, before 3.3.3 (fixed in 3.3.3); from 4.0.0, before 4.0.3 (fixed in 4.0.3); from 4.1.1, before 4.1.9 (fixed in 4.1.9); from 4.2.0, before 4.2.5 (fixed in 4.2.5); from 7.0.0, before 7.0.4 (fixed in 7.0.4); …
Published 2023-07-11. Last modified 2026-06-17.