CVE Vulnerabilities

CVE-2022-22299

Use of Externally-Controlled Format String

Published: Aug 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Fortiadc Fortinet 6.0.0 (including) 6.0.4 (including)
Fortiadc Fortinet 6.1.0 (including) 6.1.6 (including)
Fortiadc Fortinet 6.2.0 (including) 6.2.0 (including)
Fortiadc Fortinet 6.2.1 (including) 6.2.1 (including)
Fortimail Fortinet 6.4.0 (including) 6.4.5 (including)
Fortimail Fortinet 7.0.0 (including) 7.0.2 (including)
Fortiproxy Fortinet 1.0.0 (including) 1.0.7 (including)
Fortiproxy Fortinet 1.1.0 (including) 1.1.6 (including)
Fortiproxy Fortinet 1.2.0 (including) 1.2.13 (including)
Fortiproxy Fortinet 2.0.0 (including) 2.0.7 (including)
Fortiproxy Fortinet 7.0.0 (including) 7.0.0 (including)
Fortiproxy Fortinet 7.0.1 (including) 7.0.1 (including)
Fortios Fortinet 5.0.0 (including) 5.0.14 (including)
Fortios Fortinet 5.2.0 (including) 5.2.15 (including)
Fortios Fortinet 5.4.0 (including) 5.4.13 (including)
Fortios Fortinet 5.6.0 (including) 5.6.14 (including)
Fortios Fortinet 6.0.0 (including) 6.0.14 (including)
Fortios Fortinet 6.2.0 (including) 6.2.10 (including)
Fortios Fortinet 6.4.0 (including) 6.4.8 (excluding)
Fortios Fortinet 7.0.0 (including) 7.0.2 (excluding)

Potential Mitigations

References