THREAT OPS › CVEs › CVE-2022-40684
CVE-2022-40684 — Fortinet Multiple Products Authentication Bypass Vulnerability
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Vulnerability details
- Affected productsMultiple Products
- KEV remediation due2022-11-01
Related reporting
- [NVD] CVE-2022-40684 (CRITICAL 9.8) — An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacknvd
- [Security Blog] StrikeShark Campaign Exploits Known Vulnerabilities to Deploy Cobalt Strike via SharkLoaderhkcert
- June 2026 CVE Landscaperecordedfuture