Skip to main content

Critical authentication bug in Fortinet products actively exploited in the wild


Martin.1
Popular Voice
Forum|alt.badge.img+4

Fortinet is urging customers to patch a critical authentication bypass vulnerability that has already been exploited in the wild.

Earlier this month, the networking vendor patched the bug, CVE-2022-40684, found in its FortiOS network operating system, FortiProxy secure web proxy, and FortiSwitchManager management platform projects.

The vulnerability allows an unauthenticated attacker to add an SSH key to the admin user, enabling potential miscreants to hack the administrative interface using specially crafted HTTP or HTTPS requests.

The issue affects FortiOS versions from 7.0.0 to 7.0.6 and from 7.2.0 to 7.2.1, FortiProxy versions from 7.0.0 to 7.0.6 and 7.2.0, and FortiSwitchManager versions 7.0.0 and 7.2.0.

 

Full article: https://portswigger.net/daily-swig/critical-authentication-bug-in-fortinet-products-actively-exploited-in-the-wild

5 replies

russell.harris
Popular Voice
Forum|alt.badge.img+5

Forwarded to the network team. They’re usually on top of these but always best to forward on 


Martin.1
Popular Voice
Forum|alt.badge.img+4
  • Author
  • Popular Voice
  • 424 replies
  • October 26, 2022

@russell.harris  Fortunately our guys picked up on the previous article and the few fortigates we have out there are patched. 


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

russell.harris
Popular Voice
Forum|alt.badge.img+5
Jasper_The_Rasper wrote:

Cool. Thanks as always @Jasper_The_Rasper 


Jamesharris85
New Voice
Forum|alt.badge.img+4

Thanks guys, I think I already made the team aware of this one but will check and distribute if required. Cheers as always for sharing and raising awareness!


Reply