EXPOSURES › CVE-2022-42475
CVE-2022-42475
CRITICAL ⌖ ON CISA KEV · EXPLOITEDFortinet FortiOS SSL-VPN suffered a heap-based buffer overflow allowing unauthenticated remote code execution.
An unauthenticated remote attacker could execute arbitrary code via crafted requests to FortiOS SSL-VPN, enabling ransomware deployment and network compromise. DIB organizations must ensure all FortiOS versions are patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns. The failure highlights the risk of relying on core security infrastructure with known, unpatched vulnerabilities.
Shame score — A critical RCE in a core security product was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching known vulnerabilities.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.