CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Nov 1, 2022
Description
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
EPSS — Exploit Probability
94.4%
Higher than 100.0% of all CVEs
Required Action
https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684
Risk Assessment
CRITICALIn CISA KEV
High EPSS
Ransomware
Details
- Severity
- High
- EPSS
- 94.4%
- CISA KEV
- Yes
- Ransomware
- Known
- Articles
- 0
Timeline
Published
Oct 11, 2022
Added to KEV
Oct 11, 2022
Remediation Due
Nov 1, 2022