CVE-2022-35843: SSH authentication bypass when RADIUS authentication is used
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0 all versions may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Access-Challenge response from the Radius server.
Other sources
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Access-Challenge response from the Radius server.
— FortiGuard
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-35843?
CVE-2022-35843 is an authentication bypass vulnerability in the FortiOS SSH login component and FortiProxy SSH login component.
What is the severity of CVE-2022-35843?
CVE-2022-35843 has a severity level of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-35843?
CVE-2022-35843 affects Fortinet FortiOS versions 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, and Fortinet FortiProxy versions 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, and 1.2.0 all versions.
How does CVE-2022-35843 impact authentication?
CVE-2022-35843 allows for an authentication bypass by assumed-immutable data vulnerability.
Where can I find more information about CVE-2022-35843?
More information about CVE-2022-35843 can be found at https://fortiguard.com/psirt/FG-IR-22-255.