{"api_version":"1","generated_at":"2026-04-23T09:41:02+00:00","cve":"CVE-2022-40679","urls":{"html":"https://cve.report/CVE-2022-40679","api":"https://cve.report/api/cve/CVE-2022-40679.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-40679","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-40679"},"summary":{"title":"CVE-2022-40679","description":"An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2023-04-11 17:15:00","updated_at":"2023-11-07 03:52:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://fortiguard.com/psirt/FG-IR-22-335","name":"https://fortiguard.com/psirt/FG-IR-22-335","refsource":"MISC","tags":["Vendor Advisory"],"title":"PSIRT Advisories | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-40679","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-40679","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"40679","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiadc","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"40679","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiddos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"40679","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiddos-f","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"40679","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiddos-f","cpe6":"6.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2022-40679","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Execute unauthorized code or commands","cweId":"CWE-78"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"FortiDDoS","version":{"version_data":[{"version_affected":"<=","version_name":"5.6.0","version_value":"5.6.1"},{"version_affected":"<=","version_name":"5.5.0","version_value":"5.5.1"},{"version_affected":"<=","version_name":"5.4.0","version_value":"5.4.2"},{"version_affected":"<=","version_name":"5.3.0","version_value":"5.3.1"},{"version_affected":"=","version_value":"5.2.0"},{"version_affected":"=","version_value":"5.1.0"},{"version_affected":"=","version_value":"5.0.0"},{"version_affected":"=","version_value":"4.7.0"},{"version_affected":"=","version_value":"4.6.0"},{"version_affected":"=","version_value":"4.5.0"},{"version_affected":"<=","version_name":"4.4.0","version_value":"4.4.2"},{"version_affected":"<=","version_name":"4.3.0","version_value":"4.3.2"},{"version_affected":"<=","version_name":"4.2.1","version_value":"4.2.2"},{"version_affected":"<=","version_name":"4.1.1","version_value":"4.1.12"},{"version_affected":"<=","version_name":"4.0.0","version_value":"4.0.1"}]}},{"product_name":"FortiDDoS-F","version":{"version_data":[{"version_affected":"=","version_value":"6.4.0"},{"version_affected":"<=","version_name":"6.3.0","version_value":"6.3.3"},{"version_affected":"<=","version_name":"6.2.0","version_value":"6.2.2"},{"version_affected":"<=","version_name":"6.1.0","version_value":"6.1.4"}]}},{"product_name":"FortiADC","version":{"version_data":[{"version_affected":"=","version_value":"7.1.0"},{"version_affected":"<=","version_name":"7.0.0","version_value":"7.0.3"},{"version_affected":"<=","version_name":"6.2.0","version_value":"6.2.4"},{"version_affected":"<=","version_name":"6.1.0","version_value":"6.1.6"},{"version_affected":"<=","version_name":"6.0.0","version_value":"6.0.4"},{"version_affected":"<=","version_name":"5.4.0","version_value":"5.4.5"},{"version_affected":"<=","version_name":"5.3.0","version_value":"5.3.7"},{"version_affected":"<=","version_name":"5.2.0","version_value":"5.2.8"},{"version_affected":"<=","version_name":"5.1.0","version_value":"5.1.7"},{"version_affected":"<=","version_name":"5.0.0","version_value":"5.0.4"}]}}]}}]}},"references":{"reference_data":[{"url":"https://fortiguard.com/psirt/FG-IR-22-335","refsource":"MISC","name":"https://fortiguard.com/psirt/FG-IR-22-335"}]},"solution":[{"lang":"en","value":"Please upgrade to FortiDDoS-F version 6.4.1 or above\r\nPlease upgrade to FortiDDoS-F version 6.3.4 or above\r\nPlease upgrade to FortiDDoS-F version 6.2.3 or above\r\nPlease upgrade to FortiDDoS-F version 6.1.5 or above\n\r\nPlease upgrade to FortiDDoS version 5.7.0 or above\n\r\nPlease upgrade to FortiADC version 7.1.1 or above\r\nPlease upgrade to FortiADC version 7.0.4 or above\r\nPlease upgrade to FortiADC version 6.2.5 or above"}],"impact":{"cvss":[{"version":"3.1","attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"}]}},"nvd":{"publishedDate":"2023-04-11 17:15:00","lastModifiedDate":"2023-11-07 03:52:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiddos-f:6.4.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiddos-f:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3.0","versionEndExcluding":"6.3.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiddos-f:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndExcluding":"6.2.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiddos-f:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.0","versionEndExcluding":"6.1.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiddos:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"5.7.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"6.2.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}