← العودة للجدول
CVE-2022-40684
CVE-2022-40684 — An authentication bypass using an alternate path or channel [CWE-288] in Fortine
📅 2022-10-18
🔴 Critical 🔥 Yes NVD Exploit Fortinet CVSS 9.8 🎯 EPSS 94.43%

📋 الوصف الكامل

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

💻 الأنظمة المتأثرة

Fortinet FortiOS | Fortinet | Apple iOS

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2022-40684

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v7.2.0 | Fortinet PSIRT Advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←