cve-2022-40684
CRITICAL CVSS 9.8 cisa_known_exploited
Description
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Timeline
- Published
- 2022-10-11
- Last Modified
- 2022-10-11
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.8,
"datePublished": "2022-10-11",
"dateUpdated": "2022-10-11",
"description": "Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.",
"dueDate": "2022-11-01",
"id": "CVE-2022-40684",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Known",
"notes": "https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684",
"product": "Multiple Products",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "Fortinet Multiple Products Authentication Bypass Vulnerability",
"vendor": "Fortinet"
}
Enrichment data
Aggregated bundle (all enrichments)