An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiproxy | — | Upgrade FortiProxy to 7.0.7Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 7.2.1 | Sep 30, 2026 | Oct 10, 2022 |
| Fortinet Fortiswitchmanager | — | Upgrade to the latest version of FortiSwitchManagerUpgrade FortiSwitchManager to 7.2.1Upgrade FortiSwitchManager to 7.0.1 | Sep 30, 2026 | Oct 10, 2022 |
| Fortios | — | Upgrade FortiOS to 7.2.2Upgrade FortiOS to 7.0.7 | Oct 10, 2022 | Oct 10, 2022 |
| Fortiproxy | — | Upgrade to the latest version of Fortinet FortiProxy | Oct 10, 2022 | Oct 7, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub