CVE-2022-40682: High severity fortinet forticlient ssl vpn vulnerability
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-40682.
What is the severity of CVE-2022-40682?
The severity of CVE-2022-40682 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2022-40682?
Fortinet FortiClient (Windows) versions 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9, and 6.0.0 - 6.0.10 are affected by CVE-2022-40682.
How can an attacker exploit CVE-2022-40682?
An attacker can exploit CVE-2022-40682 by sending a crafted request to a specific named pipe, allowing them to execute unauthorized code or commands.
Is there a fix available for CVE-2022-40682?
Yes, Fortinet has released a security advisory with steps to mitigate the vulnerability. Please refer to the Fortinet PSIRT advisory FG-IR-22-336 for more information.