CVE-2022-42475
A heap-based buffer overflow vulnerability [CWE-122]Â in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
- Affected products
- Fortios, Fortiproxy Ssl-Vpn
- Fortinet Fortios
- ≤ 5.0.14, 5.2.15, 5.4.13, 5.6.14, 6.0.16, 6.2.12, 6.4.11, 7.0.9, 7.2.3
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.5% (100th percentile)
- Weakness
- CWE-197, CWE-787
- NVD status
- Analyzed
- Published
- 2023-01-02
Fix
Please upgrade to FortiOS version 7.2.3 or above Please upgrade to FortiOS version 7.0.9 or above Please upgrade to FortiOS version 6.4.11 or above Please upgrade to FortiOS version 6.2.12 or above Please upgrade to FortiOS version 6.0.16 or above Please upgrade to upcoming FortiOS-6K7K version 7.0.8 or above Please upgrade to FortiOS-6K7K version 6.4.10 or above Please upgrade to FortiOS-6K7K version 6.2.12 or above Please upgrade to FortiOS-6K7K version 6.0.15 or above Please upgrade to FortiProxy version 7.2.2 or above Please upgrade to FortiProxy version 7.0.8 or above Please upgrade to upcoming FortiProxy version 2.0.12 or above
10 known exploits for CVE-2022-42475
Proof-of-concept code and exploit modules indexed by Sploitus