CVE-2022-40684: Authentication bypass in administrative interface

Published Oct 10, 2022
·
Updated

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Other sources

An authentication bypass using an alternate path or channel vulnerability [CWE-288] in FortiOS, FortiProxy and FortiSwitchManager may allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.## Exploitation Status:Fortinet is aware of an instance where this vulnerability was exploited, and recommends immediately validating your systems against the following indicator of compromise in the device's logs:user=LocalProcessAccessPlease contact customer support for assistance.## UPDATE:Fortinet is aware of instances where this vulnerability was exploited to download the config file from the targeted devices, and to add a malicious superadmin account called 'fortigate-tech-support':<br/># show system admin<br/>edit fortigate-tech-support<br/>set accprofile superadmin<br/>set vdom root<br/>set password ENC [...]<br/>next<br/>Please contact customer support for assistance.## Workaround:## FortiOS:Disable HTTP/HTTPS administrative interfaceORLimit IP addresses that can reach the administrative interface:<br/>config firewall address<br/>edit myallowedaddresses<br/>set subnet <MY IP> <MY SUBNET><br/>end<br/>Then create an Address Group:<br/>config firewall addrgrp<br/>edit MGMTIPs<br/>set member myallowedaddresses<br/>end<br/>Create the Local in Policy to restrict access only to the predefined group on management interface (here: port1):<br/>config firewall local-in-policy<br/>edit 1<br/>set intf port1<br/>set srcaddr MGMTIPs<br/>set dstaddr all<br/><br/>set action accept<br/>set service HTTPS HTTP<br/>set schedule always<br/><br/>set status enable<br/>next<br/><br/>edit 2<br/>set intf any<br/>set srcaddr all<br/>set dstaddr all<br/>set action deny<br/>set service HTTPS HTTP<br/>set schedule always<br/>set status enable<br/>end<br/>If using non default ports, create appropriate service object for GUI administrative access:<br/>config firewall service custom<br/>edit GUIHTTPS<br/>set tcp-portrange admin-sport<br/>next<br/><br/>edit GUIHTTP<br/><br/>set tcp-portrange admin-port<br/>end<br/>Use these objects instead of 'HTTPS HTTP' in the local-in policy 1 and 2 below.UPDATE: When using an HA reserved management interface, the local in policy needs to be configured slightly differently - please see: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-a-local-in-policy-on-a-HA/ta-p/222005https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-a-local-in-policy-on-a-HA/ta-p/222005Please contact customer support for assistance.## FortiProxy:Disable HTTP/HTTPS administrative interfaceORFor FortiProxy VM all versions or FortiProxy appliance 7.0.6:Limit IP addresses that can reach the administrative interface (here: port1):<br/>config system interface<br/>edit port1<br/>set dedicated-to management<br/>set trust-ip-1 &lt;MY IP&gt; &lt;MY SUBNET<br/>end<br/>Please contact customer support for assistance.## FortiSwitchManager:DIsable HTTP/HTTPS administrative interfacePlease contact customer support for assistance.

FortiGuard

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CISA

Affected Software

7 affected components
Fortinet FortiProxy>=7.0.0<7.0.7
Fortinet FortiProxy=7.2.0
Fortinet FortiSwitchManager=7.0.0
Fortinet FortiSwitchManager=7.2.0
Fortinet FortiOS>=7.0.0<7.0.7
Fortinet FortiOS>=7.2.0<7.2.2
Fortinet Multiple Products

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.2.1
  2. Upgrade

    Upgrade FortiSwitchManager to a version that resolves this vulnerability.

    Fixed in 7.2.1
  3. Compensating control

    FortiOS workaround: disable HTTP/HTTPS administrative interface OR limit IP addresses that can reach the administrative interface by configuring firewall address objects and groups and applying a local-in-policy on port1 to accept only MGMT_IPs and deny all others for services HTTPS and HTTP (using GUI_HTTPS/GUI_HTTP custom service objects if using non-default ports).

  4. Compensating control

    FortiProxy workaround: disable HTTP/HTTPS administrative interface OR (for FortiProxy VM all versions or FortiProxy appliance 7.0.6) limit IP addresses that can reach the administrative interface by setting config system interface edit port1, dedicated-to management, and trust-ip-1 to the allowed <MY IP> <MY SUBNET>.

  5. Compensating control

    FortiSwitchManager workaround: disable HTTP/HTTPS administrative interface.

  6. Operational

    Immediately validate systems against the indicator of compromise in device logs: user=Local_Process_Access.

  7. Operational

    If compromise is suspected/confirmed, customer reports include a malicious super_admin account creation named 'fortigate-tech-support' (shown via 'show system admin' -> edit fortigate-tech-support -> set accprofile super_admin -> set vdom root). Contact customer support for assistance.

Event History

Oct 10, 2022
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 11, 2022
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Oct 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 18, 2024
News Published
via The Register·07:00 PM
News Published
via The Register·07:03 PM
Jan 17, 2025
News Published
via Dark Reading·07:44 PM
News Published
via Dark Reading·08:11 PM
Jan 23, 2025
News Published
via The Register·02:45 PM
Apr 16, 2025
Exploit Published
12:00 AM
Nov 14, 2025
News Published
via BleepingComputer·05:00 PM
News Published
via BleepingComputer·05:02 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for the Fortinet authentication bypass vulnerability?

The vulnerability ID for the Fortinet authentication bypass vulnerability is CVE-2022-40684.

2

Which Fortinet products are affected by the authentication bypass vulnerability?

The Fortinet authentication bypass vulnerability affects FortiOS, FortiProxy, and FortiSwitchManager, which are part of the Fortinet Multiple Products.

3

How does the authentication bypass vulnerability in Fortinet Multiple Products work?

The authentication bypass vulnerability in Fortinet Multiple Products allows an unauthenticated attacker to perform operations on the administrative interface through crafted HTTP or HTTPS requests.

4

Is authentication required to exploit the Fortinet authentication bypass vulnerability?

No, authentication is not required to exploit the Fortinet authentication bypass vulnerability.

5

Where can I find more information about the Fortinet authentication bypass vulnerability?

You can find more information about the Fortinet authentication bypass vulnerability at the following reference: [Fortinet PSIRT Advisory FG-IR-22-377](https://www.fortiguard.com/psirt/FG-IR-22-377).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203