CVE-2022-26122
Summary
| CVE | CVE-2022-26122 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-02 12:15:00 UTC |
| Updated | 2022-11-04 13:20:00 UTC |
| Description | An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Antivirus Engine | 0.4.23 | All | All | All |
| Application | Fortinet | Antivirus Engine | 2.0.49 | All | All | All |
| Application | Fortinet | Antivirus Engine | 2.0.60 | All | All | All |
| Application | Fortinet | Antivirus Engine | 4.4.54 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.137 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.142 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.144 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.145 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.156 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.157 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.243 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.252 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.253 | All | All | All |
| Application | Fortinet | Antivirus Engine | 6.33 | All | All | All |
| Application | Fortinet | Fortimail | 4.1.0 | All | All | All |
| Application | Fortinet | Fortimail | All | All | All | All |
| Application | Fortinet | Fortimail | All | All | All | All |
| Application | Fortinet | Fortimail | All | All | All | All |
| Application | Fortinet | Fortimail | All | All | All | All |
| Operating System | Fortinet | Fortios | 7.2.0 | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PSIRT Advisories | FortiGuard | CONFIRM | fortiguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43976 FortiOS - AV Engine - Evasion By Manipulating MIME Attachment Vulnerability (FG-IR-22-074)