CyberSec.Space Logo
Back to CVE Browser

CVE-2022-40684

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-10-18
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Affected Platforms (CPE)

πŸ“¦
Fortinet

Fortiproxy

>= 7.0.0 and < 7.0.7= 7.2.0
πŸ“¦
Fortinet

Fortiswitchmanager

= 7.0.0= 7.2.0
πŸ’»
Fortinet

Fortios

>= 7.0.0 and < 7.0.7>= 7.2.0 and < 7.2.2

References & Advisories

Related Vulnerabilities