RaqibCTI
CVE

CVE-2022-40684

P1⬤ KNOWN RANSOMWARE USE
Fortinet Multiple Products Authentication Bypass Vulnerability
Fortinet · Multiple Products
Date added (CISA)
2022-10-11
Remediation due
2022-11-01
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Source: NVD ↗ · CISA KEV Catalog ↗