CVE-2022-40684
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Fortinet Multiple Products Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-287
מוצרים מושפעים
fortinet: fortiproxy; fortinet: fortiswitchmanager; fortinet: fortios
קישורים
- https://fortiguard.com/psirt/FG-IR-22-377 MitigationVendor Advisory
- https://fortiguard.com/psirt/FG-IR-22-377 MitigationVendor Advisory
- http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiS… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypa… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiS… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypa… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource