ZeroHour

CVE-2022-41328

KEVmass

Path Traversal in Fortinet FortiOS Exploited in Targeted Attacks

CISA: Fortinet FortiOS Path Traversal Vulnerability

CVSS 3.1
7.1 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2022-41328 is a path traversal flaw (CWE-22) in Fortinet FortiOS in which the system fails to properly limit file paths, allowing crafted CLI commands to escape the restricted directory. A privileged attacker — one who already has CLI access to the device — can issue these crafted commands to read and write arbitrary files on the underlying Linux system, effectively breaking out of the FortiOS CLI sandbox. That post-compromise capability is valuable for stealth and persistence, since changes to system files on the underlying OS may not be visible through normal FortiOS administration. Organizations running FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.9, or any release before 6.4.11 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-14, carries a high EPSS score (10.7% probability of exploitation within 30 days, 96th percentile), and public reporting describes its use in targeted cyberattacks on government entities attributed to the espionage group tracked as UNC3886, though no public proof-of-concept code is known.

What to do: Upgrade all affected FortiGate/FortiOS devices to a fixed release beyond the affected ranges — 7.2.4 or later, 7.0.10 or later, or 6.4.11 or later — per Fortinet's advisory, as required by the CISA KEV entry. Restrict privileged CLI access (admin accounts, trusted-host/local-in policies) and review CLI logs plus the underlying Linux filesystem for unexpected file changes as signs of compromise, particularly on government or otherwise high-value networks given UNC3886 targeting.

Affected
Fortinet FortiOS7.2.0 through 7.2.3
Fortinet FortiOS7.0.0 through 7.0.9
Fortinet FortiOSall versions before 6.4.11
Estimated exposure
masshundreds of thousands of FortiGate deployments (well over 100,000 internet-facing FortiGates appear in public scans) — FortiGate is one of the most widely deployed firewall/NGFW platforms and public internet scans have repeatedly shown on the order of hundreds of thousands of exposed FortiGate endpoints, a large share of which run the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
fortios
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news