CVE-2022-22297

MEDIUM

FortiWeb/FortiRecorder <6.4.1/<6.3.17 - Info Disclosure

Title source: llm
STIX 2.1

Description

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, FortiWeb all versions 6.0, FortiRecorder version 6.4.0 through 6.4.3, FortiRecorder all versions 6.0, FortiRecorder all versions 2.7 may allow an authenticated user to read arbitrary files via specially crafted command arguments.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-792
Status published
Products (2)
fortinet/fortirecorder_firmware 2.7.0 - 2.7.7
fortinet/fortiweb 6.0.0 - 6.0.8
Published Mar 07, 2023
Tracked Since Feb 18, 2026