Zurück zur CVE-Übersicht
CVE-2022-40684
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk Signal Score84/100 — KRITISCH
- CVSS 9.8 — Kritisch
- EPSS 100% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
Artikel
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
100%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
Beschreibung
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Referenzen
- http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwi...
- http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass...
- https://fortiguard.com/psirt/FG-IR-22-377
- http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwi...
- http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass...
- https://fortiguard.com/psirt/FG-IR-22-377
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-...