CVE-2022-40684
Fortinet Multiple Products Authentication Bypass Vulnerability
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Actief misbruikt. Toegevoegd aan de CISA KEV-catalogus op 11 okt. Vereiste actie: Apply updates per vendor instructions. Bekend gebruik in ransomwarecampagnes.