Back

CRITICAL KEV Used in ransomware campaigns

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests

Published Oct 18, 2022 ·Due Nov 1, 2022

Description

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner fortinet
Published Oct 18, 2022
Updated Aug 6, 2026
Reserved Sep 14, 2022

CISA Vulnrichment

Updated Oct 23, 2024

NVD

Status Analyzed
Modified Aug 6, 2026

Red Hat

No data

ENISA EUVD

Assigner fortinet
Published Oct 18, 2022
Updated Aug 6, 2026
Exploited since Oct 11, 2022

GitHub

No data