CVE-2022-40684
Fortinet Multiple Products Authentication Bypass Vulnerability
CVSS
9.8
Critical
EPSS
100.0%
p100
KEV
YES
Oct 11, 2022
Exploit Today
80
0-100
Published: Oct 18, 2022 · Last modified: Aug 6, 2026 · CWE-287
Product
Fortinet / Multiple Products
Vulnerability
Fortinet Multiple Products Authentication Bypass Vulnerability
Added to KEV
Oct 11, 2022
Remediate by
Nov 1, 2022
Known ransomware use
Yes
Summary description
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Required action
Apply updates per vendor instructions.
Notes
https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
- packetstormsecurity.comhttp://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.html
- fortiguard.comhttps://fortiguard.com/psirt/FG-IR-22-377
- packetstormsecurity.comhttp://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.html
- fortiguard.comhttps://fortiguard.com/psirt/FG-IR-22-377
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40684