HackerFeeds
All CVEs

CVE-2022-40684

CRITICAL9.8
CISA KEV

Published 2022-10-18 · Updated 2026-08-06 · Source psirt@fortinet.com

Description

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-287CWE-287

CISA Known-Exploited Vulnerability

Product: FortinetMultiple Products

Name: Fortinet Multiple Products Authentication Bypass Vulnerability

Date added: 2022-10-11 · Due: 2022-11-01

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD