← KEV catalog
CISA known exploited vulnerability

CVE-2022-40684

Fortinet Multiple Products Authentication Bypass Vulnerability

SOURCE FACT

Fortinet · Multiple Products

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Required action

Apply updates per vendor instructions.

CISA notes

https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?