Overview
- Description
- An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Known exploits
Data from CISA
- Vulnerability name
- Fortinet Multiple Products Authentication Bypass Vulnerability
- Exploit added on
- Oct 11, 2022
- Exploit action due
- Nov 1, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B778AD94-D279-42B4-A062-8231F14936B3", "versionEndExcluding": "7.0.7", "versionStartIncluding": "7.0.0" }, { "criteria": "cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5F302F8-482A-4DA9-BDD9-63886B202B52" }, { "criteria": "cpe:2.3:a:fortinet:fortiswitchmanager:7.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B4A6B0D-1614-443B-8EBA-A8FBC2E1A832" }, { "criteria": "cpe:2.3:a:fortinet:fortiswitchmanager:7.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B73D78B-2270-45B7-854E-F985B8D88F3B" }, { "criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A86B1AB3-F33E-461C-A19C-C3A51B47AC5F", "versionEndExcluding": "7.0.7", "versionStartIncluding": "7.0.0" }, { "criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2DDB271-0A73-4C94-B3CE-B766E99898C0", "versionEndExcluding": "7.2.2", "versionStartIncluding": "7.2.0" } ], "operator": "OR" } ] } ]