peter bassill · operator
$ cve CVE-2022-42475 JSON

CVE-2022-42475 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 99.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-01-03.

Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.47% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-197
On CISA KEVyes — remediate by 2023-01-03
Public exploitnone known
Published2023-01-02
Last modified2026-06-17

CISA KEV

NameFortinet FortiOS Heap-Based Buffer Overflow Vulnerability
Added2022-12-13
Due2023-01-03
Vendor / productFortinet / FortiOS
Ransomware useknown

Affected (23)

VendorProduct
fortinetfim-7901e
fortinetfim-7904e
fortinetfim-7910e
fortinetfim-7920e
fortinetfim-7921f
fortinetfim-7941f
fortinetfortigate-6300f
fortinetfortigate-6300f-dc
fortinetfortigate-6500f
fortinetfortigate-6500f-dc
fortinetfortigate-6501f
fortinetfortigate-6501f-dc
fortinetfortigate-6601f
fortinetfortigate-6601f-dc
fortinetfortigate-7030e
fortinetfortigate-7040e
fortinetfortigate-7060e
fortinetfortigate-7121f
fortinetfortios
fortinetfortiproxy
fortinetfpm-7620e
fortinetfpm-7620f
fortinetfpm-7630e

References

→ the Explorer  ·  watch your stack  ·  NVD