Fortinet Multiple Products Authentication Bypass Vulnerability
Summary
| CVE | CVE-2022-40684 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-18 14:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. |
Risk And Classification
EPSS: 0.944270000 probability, percentile 0.999820000 (date 2026-04-22)
CISA KEV: Listed on 2022-10-11; due 2022-11-01; ransomware use Known
Problem Types: CWE-287
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | Multiple Products |
| Name | Fortinet Multiple Products Authentication Bypass Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortios | All | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
| Application | Fortinet | Fortiproxy | 7.2.0 | All | All | All |
| Application | Fortinet | Fortiswitchmanager | 7.0.0 | All | All | All |
| Application | Fortinet | Fortiswitchmanager | 7.2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PSIRT Advisories | FortiGuard | CONFIRM | fortiguard.com | |
| Fortinet FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Fortinet 7.2.1 Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150585 FortiOS Authentication Bypass Vulnerability (CVE-2022-40684)
- 43921 FortiOS Authentication Bypass Vulnerability on Administrative Interface (HTTP/HTTPS) (FG-IR-22-377)
- 730623 FortiOS Authentication Bypass Vulnerability on Administrative Interface (HTTP/HTTPS) (FG-IR-22-377)(Unauthenticated Check)