CISA Known Exploited Vulnerability

CVE-2022-40684 Ransomware

Fortinet · Multiple Products

Fortinet Multiple Products Authentication Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-288
Ransomware Known

CISA description

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Required action

Apply updates per vendor instructions.