Skip to content
COOEY

EXPOSURES › CVE-2022-40684

CVE-2022-40684

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-40684 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedauth-bypass

An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations.

This authentication bypass allows unauthenticated access to administrative interfaces, directly violating CMMC/NIST 800-171 requirements for access control and system integrity. DIB organizations must verify patch levels on all Fortinet hardware and software, as this flaw was actively exploited in the wild and linked to ransomware campaigns. Immediate remediation requires applying vendor patches and reviewing network segmentation to limit lateral movement if an admin interface is compromised.

Shame score — A critical authentication bypass in widely deployed security hardware that was actively exploited in the wild and linked to ransomware, representing a severe negligence failure in patch management and threat monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.