CVE Vulnerabilities

CVE-2022-38372

Published: Nov 02, 2022 | Modified: Nov 04, 2022
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, privileged user to obtain a root shell on the device via an undocumented command.

Affected Software

Name Vendor Start Version End Version
Fortitester Fortinet 2.3.0 (including) 3.9.1 (including)
Fortitester Fortinet 4.0.0 (including) 4.2.0 (including)
Fortitester Fortinet 7.0.0 (including) 7.0.0 (including)
Fortitester Fortinet 7.1.0 (including) 7.1.0 (including)

References