LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-40684: Fortinet Multiple Products Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 11, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-40684 to its Known Exploited Vulnerabilities catalog on Oct 11, 2022, with a federal patch deadline of Nov 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface…

CVE-2022-40684 is an authentication bypass vulnerability affecting multiple Fortinet products, specifically FortiOS, FortiProxy, and FortiSwitchManager. It allows an unauthenticated attacker to perform operations on the administrative interface by sending specially crafted HTTP or HTTPS requests. This matters because administrative interfaces control core network and security functions; successful abuse can give attackers high-level access without credentials, and the vulnerability has been used in ransomware activity.

Defenders should treat any internet-facing or poorly segmented management interfaces on these products as high priority for verification and remediation. Confirm all product-specific details against the vendor advisory, as public information here is limited to the CISA summary and CWE classification.

How it works

The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In this case, the products fail to properly enforce authentication for certain requests directed at the administrative interface. An unauthenticated remote attacker can craft HTTP or HTTPS requests that the system processes as if they came from an authenticated administrator, enabling operations that should require valid credentials.

No further exploit mechanics, request formats, or payload details are provided in the available facts. Attackers typically target the management plane of network security appliances this way to reconfigure devices, create accounts, or pivot deeper into the environment. Because the bypass reaches the administrative interface, the impact is equivalent to full admin control once the request is accepted. Always validate the precise attack surface and conditions against the Fortinet advisory rather than assuming any particular request path.

Am I affected? How to find it in your systems

The affected software is Fortinet FortiOS, FortiProxy, and FortiSwitchManager. These commonly run on Fortinet firewalls, proxies, and switch management appliances that provide network security, SSL inspection, or centralized switch control. They are often deployed at network perimeters, in data centers, or as virtual appliances.

If management interfaces are exposed or versions match the advisory, treat the systems as potentially vulnerable until patched.

How to remediate

The primary action is to apply the updates provided by Fortinet, following the vendor instructions exactly as required by CISA. Patching closes the authentication bypass so that crafted requests can no longer reach administrative functions without proper credentials.

Document the remediation and retain evidence of the update for compliance and incident response purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the administrative interface and network path.

These steps lower the likelihood of successful exploitation but do not replace the patch.

If your data may have been exposed

This vulnerability has known ransomware use, so successful exploitation can lead to full administrative compromise, data theft, ransomware deployment, or further lateral movement. If logs or other indicators suggest the administrative interface was accessed without authorization, treat the incident as a potential breach: isolate the device, preserve forensic evidence, rotate credentials, and engage incident response processes. Organizations can also run a free exposure scan of their email addresses to check whether related credentials or data appear in known breach collections, then force password resets and enable multi-factor authentication where possible.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · Multiple Products
WeaknessCWE-288
Added to CISA KEVOct 11, 2022
Federal patch deadlineNov 1, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities