CVE-2022-30301

HIGH

FortiAP-U 5.4.0-5.4.6, 6.0.0-6.0.4, 6.2.0-6.2.3 - Authenticated Path Traversal via CLI Commands

Title source: llm
STIX 2.1

Description

A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to delete and access unauthorized files and data via specifically crafted CLI commands.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-22-109

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 29.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (6)
fortinet/fortiap-u 5.4.0
fortinet/fortiap-u 5.4.3
fortinet/fortiap-u 5.4.4
fortinet/fortiap-u 5.4.5
fortinet/fortiap-u 5.4.6
fortinet/fortiap-u 6.0.0 - 6.0.4
Published Jul 19, 2022
Tracked Since Feb 18, 2026