CVE-2022-40684
Description
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Summary dbcve.org
An authentication bypass vulnerability (CWE-288) affecting FortiOS, FortiProxy, and FortiSwitchManager allows an unauthenticated remote attacker to perform operations on the administrative interface by sending specially crafted HTTP or HTTPS requests. With a CVSS of 9.8, the flaw exposes administrative functionality without any credential requirement, potentially enabling full device compromise, configuration changes, or further lateral movement.
Mitigation
Upgrade FortiOS, FortiProxy, and FortiSwitchManager to versions outside the affected ranges (FortiOS 7.2.2+/7.0.7+, FortiProxy 7.2.1+/7.0.7+, FortiSwitchManager 7.2.1+/7.0.1+) and restrict access to the administrative interface (e.g., via trusted hosts, management VLAN, or IP allow-lists) until patching is complete.