cve-2022-40684

CRITICAL CVSS 9.8 cisa_known_exploited
Description

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Timeline
Published
2022-10-11
Last Modified
2022-10-11
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 9.8,
  "datePublished": "2022-10-11",
  "dateUpdated": "2022-10-11",
  "description": "Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.",
  "dueDate": "2022-11-01",
  "id": "CVE-2022-40684",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.fortiguard.com/psirt/FG-IR-22-377;  https://nvd.nist.gov/vuln/detail/CVE-2022-40684",
  "product": "Multiple Products",
  "requiredAction": "Apply updates per vendor instructions.",
  "severity": "CRITICAL",
  "source": "cisa_known_exploited",
  "title": "Fortinet Multiple Products Authentication Bypass Vulnerability",
  "vendor": "Fortinet"
}
Enrichment data
View JSON API Download JSON