LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-41328: Fortinet FortiOS Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 14, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 4, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-41328 to its Known Exploited Vulnerabilities catalog on Mar 14, 2023, with a federal patch deadline of Apr 4, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

CVE-2022-41328 is a path traversal vulnerability in Fortinet FortiOS. It may allow a local privileged attacker to read and write files by issuing crafted CLI commands. For IT and security teams, this matters because FortiOS commonly underpins firewalls, VPN gateways, and other network edge devices; unauthorized file access on those systems can expose configuration, credentials, or other sensitive data and enable further compromise of the device or the network it protects.

Public detail is limited to the CWE-22 classification and the CISA description above. Confirm exact impact, affected builds, and any additional conditions against the vendor advisory before acting.

How it works

The flaw belongs to the path traversal class (CWE-22). In this weakness, software fails to properly neutralize special elements such as directory traversal sequences in user-supplied input that is used to construct a file path. An attacker who already holds local privileged access can supply crafted CLI commands that cause the FortiOS component handling those commands to resolve paths outside the intended directories. Successful abuse lets the attacker read arbitrary files or write to locations that should be protected, potentially altering configuration, planting persistence, or extracting secrets. Exact command syntax and reachable paths are not detailed in the available summary; treat any CLI input that influences file operations as potentially dangerous until the vendor advisory is reviewed.

Am I affected? How to find it in your systems

FortiOS runs on Fortinet FortiGate appliances and related Fortinet network security products that provide firewall, VPN, and routing functions. These devices typically sit at network perimeters, in data centers, or as virtual instances in cloud environments.

If version or configuration details are unclear, treat the device as potentially affected until confirmed against the official advisory.

How to remediate

Apply the vendor-supplied updates for FortiOS exactly as directed in the Fortinet advisory for CVE-2022-41328. CISA’s required action is to apply updates per vendor instructions; prioritize devices that expose privileged CLI access.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface and increase detection capability.

These steps lower risk but do not eliminate the vulnerability; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to breaches in which configuration files, credentials, or other sensitive data are read or modified. Although ransomware use is not documented for this CVE, treat any confirmed exploitation as a potential data-exposure event. Review device logs for signs of unauthorized file access, reset affected credentials, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts appear in public breach compilations.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS
WeaknessCWE-22
Added to CISA KEVMar 14, 2023
Federal patch deadlineApr 4, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities