← Back

CVE-2022-42475

Published: Jan 2, 2023Modified: Oct 24, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected (18)

2 products
Fortios
Fortiproxy
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 5.0.0 to 5.0.14
From 5.2.0 to 5.2.15
From 5.4.0 to 5.4.13
From 5.6.0 to 5.6.14
From 6.0.0 to 6.0.16
From 6.4.0 to 6.4.11
From 7.0.0 to 7.0.9
From 7.2.0 to 7.2.3
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 1.0.0 to 1.0.7
From 1.1.0 to 1.1.6
From 1.2.0 to 1.2.13
From 2.0.0 to 2.0.12
From 7.0.0 to 7.0.8
From 7.2.0 to 7.2.2
Configuration C
4 vulnerable · 21 platform
Vulnerable SoftwareAffected Versions
Fortinet
From 6.0.0 to 6.0.15
From 6.2.0 to 6.2.12
From 6.4.0 to 6.4.10
From 7.0.0 to 7.0.8
Running on/withPlatform Versions
Fortinet
Fim 7901e
All versions
Fortinet
Fim 7904e
All versions
Fortinet
Fim 7910e
All versions
Fortinet
Fim 7920e
All versions
Fortinet
Fim 7921f
All versions
Fortinet
Fim 7941f
All versions
Fortinet
Fortigate 6300f
All versions
Fortinet
Fortigate 6300f Dc
All versions
Fortinet
Fortigate 6500f
All versions
Fortinet
Fortigate 6500f Dc
All versions
Fortinet
Fortigate 6501f
All versions
Fortinet
Fortigate 6501f Dc
All versions
Fortinet
Fortigate 6601f
All versions
Fortinet
Fortigate 6601f Dc
All versions
Fortinet
Fortigate 7030e
All versions
Fortinet
Fortigate 7040e
All versions
Fortinet
Fortigate 7060e
All versions
Fortinet
Fortigate 7121f
All versions
Fortinet
Fpm 7620e
All versions
Fortinet
Fpm 7620f
All versions
Fortinet
Fpm 7630e
All versions

References (3)

Source: psirt@fortinet.com
ExploitMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.