Lucene search

K
fortinetFortiGuard LabsFG-IR-22-377
HistoryOct 10, 2022 - 12:00 a.m.

Protect

2022-10-1000:00:00
FortiGuard Labs
www.fortiguard.com
172
authentication bypass
fortios
fortiproxy
fortiswitchmanager
vulnerability
http
https
unauthenticated attacker

0.974 High

EPSS

Percentile

99.9%

An authentication bypass using an alternate path or channel vulnerability [CWE-288] in FortiOS, FortiProxy and FortiSwitchManager may allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.