imPC@ndo IT

Tracker / CVE-2022-42475

CVE-2022-42475

Ransomware Critical 9.8

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected products and versions

fortinet fortios · 5.0.0 → 5.0.14
fortinet fortios · 5.2.0 → 5.2.15
fortinet fortios · 5.4.0 → 5.4.13
fortinet fortios · 5.6.0 → 5.6.14
fortinet fortios · 6.0.0 → 6.0.15
fortinet fortios · 6.0.0 → 6.0.16
fortinet fortios · 6.2.0 → 6.2.12
fortinet fortios · 6.4.0 → 6.4.10
fortinet fortios · 6.4.0 → 6.4.11
fortinet fortios · 7.0.0 → 7.0.8
fortinet fortios · 7.0.0 → 7.0.9
fortinet fortios · 7.2.0 → 7.2.3
fortinet fortiproxy · 1.0.0 → 1.0.7
fortinet fortiproxy · 1.1.0 → 1.1.6
fortinet fortiproxy · 1.2.0 → 1.2.13
fortinet fortiproxy · 2.0.0 → 2.0.12
fortinet fortiproxy · 7.0.0 → 7.0.8
fortinet fortiproxy · 7.2.0 → 7.2.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References