CVE-2022-40684
KEV
🔴 Łataj teraz
Obejście uwierzytelnienia w FortiOS umożliwia nieautoryzowanym atakującym dostęp do interfejsu administracyjnego.
CVSS
9.8
EPSS
100.0%
Exploit
weaponized
Vendor
fortinet
Opis źródłowy (NVD)
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
auth-bypass exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 100.0% |
| Opublikowano (NVD) | 2022-10-18 14:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-06 05:16:37 UTC |
Referencje
- http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html (psirt@fortinet.com) [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.html (psirt@fortinet.com) [Exploit, Third Party Advisory, VDB Entry]
- https://fortiguard.com/psirt/FG-IR-22-377 (psirt@fortinet.com) [Mitigation, Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40684 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]