Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-40684

Fortinet | Multiple ProductsAdded 2022-10-11Remediation Deadline 2022-11-01Active Ransomware Campaign

Fortinet Multiple Products Authentication Bypass Vulnerability

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-288

References