Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35843


An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Access-Challenge response from the Radius server.


Published

2022-12-06T17:15:10.873

Last Modified

2024-11-21T07:11:48.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy ≤ 1.2.13 Yes
Application fortinet fortiproxy ≤ 2.0.10 Yes
Application fortinet fortiproxy ≤ 7.0.6 Yes
Operating System fortinet fortios ≤ 6.0.15 Yes
Operating System fortinet fortios ≤ 6.2.12 Yes
Operating System fortinet fortios ≤ 6.4.9 Yes
Operating System fortinet fortios ≤ 7.0.7 Yes
Operating System fortinet fortios 7.2.0 Yes
Operating System fortinet fortios 7.2.1 Yes

References