CVE-2022-33875
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Una neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de Comando SQL ("Inyección SQL") en Fortinet FortiADC versión 7.1.0, versión 7.0.0 a 7.0.2 y versión 6.2.4 y anteriores permite a un atacante autenticado ejecutar código no autorizado o comandos a través de solicitudes HTTP específicamente manipuladas.
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-06-16 CVE Reserved
- 2022-12-06 CVE Published
- 2024-10-22 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/psirt/FG-IR-22-252 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiadc Search vendor "Fortinet" for product "Fortiadc" | >= 5.2.0 <= 6.2.4 Search vendor "Fortinet" for product "Fortiadc" and version " >= 5.2.0 <= 6.2.4" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiadc Search vendor "Fortinet" for product "Fortiadc" | 7.0.0 Search vendor "Fortinet" for product "Fortiadc" and version "7.0.0" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiadc Search vendor "Fortinet" for product "Fortiadc" | 7.0.1 Search vendor "Fortinet" for product "Fortiadc" and version "7.0.1" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiadc Search vendor "Fortinet" for product "Fortiadc" | 7.0.2 Search vendor "Fortinet" for product "Fortiadc" and version "7.0.2" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiadc Search vendor "Fortinet" for product "Fortiadc" | 7.1.0 Search vendor "Fortinet" for product "Fortiadc" and version "7.1.0" | - |
Affected
|