CVE ID
CVE-2022-40684
Vulnerability Name
Fortinet Multiple Products Authentication Bypass Vulnerability
- Project: Fortinet
- Product: Multiple Products
Date
- Date Added: 2022-10-11
- Due Date: 2022-11-01
Description
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply updates per vendor instructions.
Additional Notes
https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684
Related Security News
- New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
- ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January]
- 15K Fortinet Device Configs Leaked to the Dark Web
- Hackers leak configs and VPN credentials for 15,000 FortiGate devices
Top comments (0)