S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-40684 Scanner

CVE-2022-40684 scanner - Authentication Bypass vulnerability in Fortinet FortiOS, FortiProxy, FortiSwitchManager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
8
Times Used
by S4E users
1
Assets Scanned
domains & IPs
2
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-40684
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Fortinet FortiOS, FortiProxy, FortiSwitchManagerby Fortinet
FortiOS 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiProxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiSwitchManager 7.2.0, 7.0.0
Updated Aug 19, 2026View on NVD →
Detail

Fortinet FortiOS, FortiProxy, and FortiSwitchManager are software products used in network security and management. FortiOS is a popular operating system for Fortinet's security appliances, allowing for the management and control of network traffic, application services, and threat prevention features. FortiProxy is an application delivery controller that serves as a gateway between the client and server, offering load balancing, caching, and web application firewall functionalities. Finally, FortiSwitchManager is used to manage and monitor the FortiSwitch family of products, which offer advanced network connectivity, intelligent management, and security capabilities.

CVE-2022-40684 is a vulnerability detected in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6, and FortiSwitchManager version 7.2.0 and 7.0.0. The vulnerability is a type of authentication bypass that allows an unauthenticated attacker to perform operations on the administrative interface using specially crafted HTTP or HTTPS requests. This vulnerability can be exploited remotely to gain access to sensitive data or to take control of the device.

When exploited, this vulnerability can lead to the compromise of sensitive data, control of the device, and unauthorized access to administrative features. An attacker can exploit CVE-2022-40684 to bypass the authentication mechanism, which should prevent unauthorized access to the device's administrative interface. This vulnerability allows an attacker to control the device remotely and potentially launch further attacks within the network, causing data loss or the disruption of critical business services.

In conclusion, the CVE-2022-40684 vulnerability in Fortinet FortiOS, FortiProxy, and FortiSwitchManager can allow an attacker to bypass authentication mechanisms, leading to unauthorized access and control of the device. To protect against this vulnerability, users can take various precautions, including updating to the latest version, enabling strong passwords and multi-factor authentication, and monitoring network activity. s4e.io's pro features can quickly and easily identify vulnerabilities in digital assets, ensuring that users remain secure in an ever-changing threat landscape.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of Fortinet FortiOS, FortiProxy, and FortiSwitchManager.
  • Ensure that the device is not accessible from untrusted networks.
  • Implement strong passwords for all user accounts and administrative access.
  • Enable multi-factor authentication for all user accounts and administrative access.
  • Monitor network traffic for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.