Skip to main content

Exploit available for critical Fortinet auth bypass bug, patch now


kleinmat4103
Popular Voice
Forum|alt.badge.img+6

 

By Sergiu Gatlan  October 13, 2022

 

Proof-of-concept exploit code is now available for a critical authentication bypass vulnerability affecting Fortinet's FortiOS, FortiProxy, and FortiSwitchManager appliances.

This security flaw (CVE-2022-40684) allows attackers to bypass the authentication process on the administrative interface of FortiGate firewalls, FortiProxy web proxies, and FortiSwitch Manager (FSWM) on-premise management instances.

 

<<< Full Article Here >»


 

Patch your firewalls, people! This is serious!

8 replies

russell.harris
Popular Voice
Forum|alt.badge.img+5

Cheers for posting. We use quite a bit of Fortinet kit so I'll send this to the network team to make sure they’re aware


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Jamesharris85
New Voice
Forum|alt.badge.img+4

Thanks both, will share with the team


russell.harris
Popular Voice
Forum|alt.badge.img+5

kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Author
  • Popular Voice
  • 512 replies
  • October 14, 2022

We’re lucky this time. We don’t use Fortinet, but it’s only a matter of time before something else hits us. Sadly.

Good luck getting all your devices updated. Firewall updates usually mean a late night for someone.


russell.harris
Popular Voice
Forum|alt.badge.img+5
kleinmat4103 wrote:

We’re lucky this time. We don’t use Fortinet, but it’s only a matter of time before something else hits us. Sadly.

Good luck getting all your devices updated. Firewall updates usually mean a late night for someone.

Yep, but not for me! I no longer work in the network team, I only do projects now, so install the stuff but someone else can maintain them!


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Author
  • Popular Voice
  • 512 replies
  • October 14, 2022

Oh I see. You just get to ruin someone else’s weekend! 🤣


russell.harris
Popular Voice
Forum|alt.badge.img+5
kleinmat4103 wrote:

Oh I see. You just get to ruin someone else’s weekend! 🤣

True! I’ve done my time thank you very much!

Alrhough some of my days are spent buried in spreadsheets!