← voltar
CVE-2022-40684

CVE-2022-40684

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-287
Em resumo

Uma falha no FortiOS, FortiProxy e FortiSwitchManager permite que atacantes acessem o painel administrativo sem fazer login, usando requisições HTTP/HTTPS especialmente crafted. Isso é crítico porque dá acesso total de administrador ao sistema.

Detalhe técnico

Vulnerabilidade de autenticação em produtos Fortinet (FortiOS 7.0.0–7.0.6, 7.2.0–7.2.1; FortiProxy 7.0.0–7.0.6, 7.2.0; FortiSwitchManager 7.0.0, 7.2.0) que permite bypass de autenticação via CWE-287. Atacantes não autenticados podem acessar a interface administrativa remotamente através de requisições HTTP/HTTPS malformadas, obtendo privilégios de administrador sem pré-condições.

Resumo gerado e traduzido por IA a partir da descrição oficial.
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
PoCs públicas encontradas33
githubgithub.com/horizon3ai/CVE-2022-40684356githubgithub.com/carlosevieira/CVE-2022-4068487githubgithub.com/arsolutioner/fortigate-belsen-leak86githubgithub.com/Filiplain/Fortinet-PoC-Auth-Bypass16githubgithub.com/kljunowsky/CVE-2022-40684-POC16githubgithub.com/TaroballzChen/CVE-2022-40684-metasploit-scanner14githubgithub.com/hughink/CVE-2022-4068411githubgithub.com/qingsiweisan/CVE-2022-406849githubgithub.com/Chocapikk/CVE-2022-406847githubgithub.com/secunnix/CVE-2022-406845githubgithub.com/z-bool/CVE-2022-406845githubgithub.com/und3sc0n0c1d0/CVE-2022-406844githubgithub.com/xtwip/fortipwn4githubgithub.com/jsongmax/Fortinet-CVE-2022-406842githubgithub.com/gustavorobertux/gotigate2githubgithub.com/HAWA771/CVE-2022-406842githubgithub.com/NeriaBasha/CVE-2022-406841githubgithub.com/XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-1githubgithub.com/iveresk/CVE-2022-406841githubgithub.com/Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-406840githubgithub.com/pintukumar-sutradhar/fortigate-cve-2022-40684-tool0githubgithub.com/mhd108/CVE-2022-406840githubgithub.com/ClickCyber/cve-2022-406840githubgithub.com/puckiestyle/CVE-2022-406840githubgithub.com/notareaperbutDR34P3r/CVE-2022-40684-Rust0githubgithub.com/dkstar11q/CVE-2022-406840githubgithub.com/Anthony1500/CVE-2022-406840githubgithub.com/niklasmato/fortileak-01-2025-Be0githubgithub.com/ccordeiro/CVE-2022-406840exploitdbwww.exploit-db.com/exploits/52239não verificadocve_referencepacketstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/51092não verificadocve_referencepacketstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.htmlnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →