Skip to content
COOEY

EXPOSURES › CVE-2022-42475

CVE-2022-42475

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-12-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-42475 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Fortinet FortiOS SSL-VPN suffered a heap-based buffer overflow allowing unauthenticated remote code execution.

An unauthenticated remote attacker could execute arbitrary code via crafted requests to FortiOS SSL-VPN, enabling ransomware deployment and network compromise. DIB organizations must ensure all FortiOS versions are patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns. The failure highlights the risk of relying on core security infrastructure with known, unpatched vulnerabilities.

Shame score — A critical RCE in a core security product was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching known vulnerabilities.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.