NA

CVE-2022-26122

Published: 02/11/2022 Updated: 04/11/2022
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an malicious user to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortimail 4.1.0

fortinet fortimail

fortinet fortios

fortinet fortios 7.2.0

fortinet antivirus engine 6.33

fortinet antivirus engine 6.253

fortinet antivirus engine 6.252

fortinet antivirus engine 6.243

fortinet antivirus engine 6.157

fortinet antivirus engine 6.156

fortinet antivirus engine 6.145

fortinet antivirus engine 6.144

fortinet antivirus engine 6.142

fortinet antivirus engine 6.137

fortinet antivirus engine 4.4.54

fortinet antivirus engine 2.0.60

fortinet antivirus engine 2.0.49

fortinet antivirus engine 0.4.23