CVE-2022-35843
Summary
| CVE | CVE-2022-35843 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-06 17:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Access-Challenge response from the Radius server. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43946 FortiOS SSH Authentication Bypass Vulnerability (FG-IR-22-255)
- 44037 FortiOS SSH Authentication Bypass Vulnerability (FG-IR-22-255) (Unauthenticated check)