CVE-2022-40684

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,...

Basic Information

CVE State
PUBLISHED
Reserved Date
September 14, 2022
Published Date
October 18, 2022
Last Updated
October 23, 2024
Vendor
Fortinet
Product
Fortinet FortiOS, FortiProxy, FortiSwitchManager
Description
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-10-11 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2022-10-14 10:53:50 UTC) Source
Used in Malware
Yes (added 2022-10-11 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-10-11 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

fortinet_authentication_bypass_cve_2022_40684

Type: metasploit • Created: Unknown

Metasploit module for CVE-2022-40684

z-bool/CVE-2022-40684

Type: github • Created: 2023-02-27 18:05:34 UTC • Stars: 5

一键枚举所有用户名以及写入SSH公钥

hughink/CVE-2022-40684

Type: github • Created: 2022-10-28 03:46:00 UTC • Stars: 10

TaroballzChen/CVE-2022-40684-metasploit-scanner

Type: github • Created: 2022-10-27 15:11:27 UTC • Stars: 14

An authentication bypass using an alternate path or channel in Fortinet product

qingsiweisan/CVE-2022-40684

Type: github • Created: 2022-10-26 01:48:14 UTC • Stars: 10

und3sc0n0c1d0/CVE-2022-40684

Type: github • Created: 2022-10-19 22:07:24 UTC • Stars: 4

Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).

jsongmax/Fortinet-CVE-2022-40684

Type: github • Created: 2022-10-17 09:22:57 UTC • Stars: 2

HAWA771/CVE-2022-40684

Type: github • Created: 2022-10-15 19:43:48 UTC • Stars: 2

Fortinet Critical Authentication Bypass Vulnerability (CVE-2022-40684) [ Mass Exploit ]

mohamedbenchikh/CVE-2022-40684

Type: github • Created: 2022-10-15 17:02:49 UTC • Stars: 4

Exploit for CVE-2022-40684 vulnerability

Chocapikk/CVE-2022-40684

Type: github • Created: 2022-10-15 16:51:25 UTC • Stars: 5

Fortinet Critical Authentication Bypass Vulnerability (CVE-2022-40684) [ Mass Exploit ]

iveresk/CVE-2022-40684

Type: github • Created: 2022-10-14 10:53:50 UTC • Stars: 1

secunnix/CVE-2022-40684

Type: github • Created: 2022-10-14 01:07:01 UTC • Stars: 5

kljunowsky/CVE-2022-40684-POC

Type: github • Created: 2022-10-13 21:07:50 UTC • Stars: 15

Exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

carlosevieira/CVE-2022-40684

Type: github • Created: 2022-10-13 18:13:59 UTC • Stars: 87

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

horizon3ai/CVE-2022-40684

Type: github • Created: 2022-10-13 14:24:12 UTC • Stars: 349

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager