CyberSec.Space Logo
Back to CVE Browser

CVE-2022-42475

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-01-02
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected Platforms (CPE)

💻
Fortinet

Fortios

>= 5.0.0 and <= 5.0.14>= 5.2.0 and <= 5.2.15>= 5.4.0 and <= 5.4.13>= 5.6.0 and <= 5.6.14>= 6.0.0 and < 6.0.16>= 6.2.0 and < 6.2.12>= 6.4.0 and < 6.4.11>= 7.0.0 and < 7.0.9>= 7.2.0 and < 7.2.3>= 6.0.0 and < 6.0.15>= 6.4.0 and < 6.4.10>= 7.0.0 and < 7.0.8
📦
Fortinet

Fortiproxy

>= 1.0.0 and <= 1.0.7>= 1.1.0 and <= 1.1.6>= 1.2.0 and <= 1.2.13>= 2.0.0 and < 2.0.12>= 7.0.0 and < 7.0.8>= 7.2.0 and < 7.2.2

References & Advisories

Related Vulnerabilities