Junglewise Threat Intelligence

CVE-2022-40684: Fortinet Multiple Products Authentication Bypass Vulnerability

CVE-2022-40684 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-10-11

Technologies: Fortinet FortiSwitchManager, Fortinet FortiOS, Apple Multiple Products, Fortinet FortiProxy. Vendors: Fortinet, Apple.

Executive brief

An authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiSwitchManager allows unauthenticated attackers to perform administrative operations. The flaw is exploited via specially crafted HTTP or HTTPS requests targeting the administrative interface.

Affected products

  • Fortinet FortiOS 7.0.0 - 7.0.6, 7.2.0 - 7.2.1
  • Fortinet FortiProxy 7.0.0 - 7.0.6, 7.2.0
  • Fortinet FortiSwitchManager 7.0.0, 7.2.0

Timeline

  • 2022-10-11: disclosed: Published date per advisory title
  • 2022-10-11: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-10-18: advisory: NVD Published Date
  • 2022-10-11: exploited: Reported exploited in the wild per advisory metadata and CISA KEV entry

Related threats