Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-40684
HistoryOct 18, 2022 - 2:15 p.m.

Authentication flaw

2022-10-1814:15:00
PRIOn knowledge base
www.prio-n.com
11
authentication flaw
cwe-288
fortinet fortios
fortiproxy
fortiswitchmanager
unauthenticated attacker
administrative interface
http
https requests

9.7 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.