Umbra Wiki cve cve/CVE-2022-40684
Back to wiki

CVE-2022-40684 — Fortinet Multiple Products Authentication Bypass Vulnerability

provenance: imported · CVE: CVE-2022-40684

CVE-2022-40684: Fortinet Multiple Products Authentication Bypass Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Fortinet
Product Multiple Products
Date added 2022-10-11
Due date 2022-11-01
Ransomware campaign use Known

Description

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-40684
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog