QID 43921

Date Published: 2022-10-08

QID 43921: FortiOS Authentication Bypass Vulnerability on Administrative Interface (HTTP/HTTPS) (FG-IR-22-377)

An authentication bypass using an alternate path or channel [CWE-88] in FortiOS may allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Affected Products:
FortiOS version from 7.0.0 to 7.0.6
FortiOS version from 7.2.0 to 7.2.1

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable version of FortiOS may allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer to FG-IR-22-377Workaround:
    Please refer to FG-IR-22-377 for information on workaround.

    Vendor References

    CVEs related to QID 43921

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-377 URL Logo www.fortiguard.com/psirt/FG-IR-22-377