SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-40684

Fortinet Multiple Products Authentication Bypass Vulnerability

KEVCRITICAL 9.8EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 November 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.98% probability · 100th percentile
CISA KEV
Listed 11 October 2022 · due 1 November 2022 · used in ransomware campaigns
Weakness
CWE-287
Affected
fortinet/fortiproxy · fortinet/fortiswitchmanager · fortinet/fortios
Source
psirt@fortinet.com

CISA notes

Apply updates per vendor instructions. https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.