PT-2022-24395 · Fortinet · Fortitester Cli

Published

2022-11-02

·

Updated

2022-11-04

·

CVE-2022-38372

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiTester CLI versions 2.3.0 through 3.9.1 FortiTester CLI versions 4.0.0 through 4.2.0 FortiTester CLI versions 7.0.0 through 7.1.0
Description A hidden functionality issue may allow a local, privileged user to obtain a root shell on the device via an undocumented command.
Recommendations For FortiTester CLI versions 2.3.0 through 3.9.1, update to a version outside of this range to resolve the issue. For FortiTester CLI versions 4.0.0 through 4.2.0, update to a version outside of this range to resolve the issue. For FortiTester CLI versions 7.0.0 through 7.1.0, update to a version outside of this range to resolve the issue.

Fix

Related Identifiers

CVE-2022-38372

Affected Products

Fortitester Cli