CVE-2022-40684β€”Fortinet Multiple Products Authentication Bypass Vulnerability

PUBLISHEDvulnerability record
2022-10-11 Β· last modified June 21, 2025

Metadata

CVE ID:
CVE-2022-40684
Project:
Fortinet
Product:
Multiple Products
Date Added:
2022-10-11
Due Date:
2022-11-01
Last Updated:
June 21, 2025

Vulnerability Name

Fortinet Multiple Products Authentication Bypass Vulnerability

Description

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related News Articles

Related Weaknesses