---
cve: "CVE-2022-40684"
severity: "CRITICAL"
cvss: 9.8
epss: "100%"
vendor: "Fortinet"
kev: true
exploited: true
published: "2022-10-18 14:15:09"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T02:30:16+02:00"
---

# CVE-2022-40684

> 9.8 CRITICAL · ⚠️ CISA KEV (1428 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-288** — Authentication Bypass Using an Alternate Path or Channel
  The product requires authentication, but the product has an alternate path or channel that does not require authentication.

## Angriffsmuster (CAPEC)

- [CAPEC-127 — Directory Indexing](https://capec.mitre.org/data/definitions/127.html) _(Severity: Medium)_
- [CAPEC-665 — Exploitation of Thunderbolt Protection Flaws](https://capec.mitre.org/data/definitions/665.html) _(Severity: Very High)_

## ATT&CK-Techniken

- [T1083 — File and Directory Discovery](https://attack.mitre.org/techniques/T1083/)
- [T1211 — Exploitation for Defensive Evasion](https://attack.mitre.org/techniques/T1211/)
- [T1542.002 — Pre-OS Boot: Component Firmware](https://attack.mitre.org/techniques/T1542/002/)
- [T1556 — Modify Authentication Process](https://attack.mitre.org/techniques/T1556/)

## Exploit-Evidenz

- [EDB-52239 — Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass](https://www.exploit-db.com/exploits/52239)
- [EDB-51092 — FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass](https://www.exploit-db.com/exploits/51092)

## Referenzen

- <https://fortiguard.com/psirt/FG-IR-22-377>
- <http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html>
- <http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.html>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40684>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-40684) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
