NA

CVE-2022-35843

Published: 06/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 up to and including 7.0.7, 6.4.0 up to and including 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 up to and including 7.0.5, 2.0.0 up to and including 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated malicious user to login into the device via sending specially crafted Access-Challenge response from the Radius server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortiproxy

fortinet fortios 7.2.0

fortinet fortios

fortinet fortios 7.2.1