CVE-2022-42475
Description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Summary dbcve.org
A heap-based buffer overflow (CWE-122) exists in the SSL-VPN component of FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it with specifically crafted requests to achieve arbitrary code execution on the appliance, yielding full system compromise on a perimeter device exposed for remote-access VPN.
Mitigation
Immediately upgrade FortiOS and FortiProxy SSL-VPN to a fixed version per Fortinet's advisory, restrict SSL-VPN management/reachability to trusted networks where feasible, and monitor the device for indicators of compromise given prior mass-exploitation of Fortinet SSL-VPN flaws.