CVE Feed

    Dashboard / CVE / CVE-2022-42475

    CVE-2022-42475

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

    Published:Jan 2, 2023
    Last Modified:Oct 24, 2025
    EPS:Jan 2, 2023
    EPSS Score:0.9394
    CVSS Score:9.3

    CISA Notification

    Description

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Jan 3, 2023
    1347 days ago
    Alert Date
    Dec 13, 2022
    1368 days ago

    Affected Products

    Vendor
    Fortinet
    Product
    Fim-7901e
    Vendor
    Fortinet
    Product
    Fim-7904e
    Vendor
    Fortinet
    Product
    Fim-7910e
    Vendor
    Fortinet
    Product
    Fim-7920e
    Vendor
    Fortinet
    Product
    Fim-7921f
    Vendor
    Fortinet
    Product
    Fim-7941f
    Vendor
    Fortinet
    Product
    Fortigate-6300f
    Vendor
    Fortinet
    Product
    Fortigate-6300f-dc
    Vendor
    Fortinet
    Product
    Fortigate-6500f
    Vendor
    Fortinet
    Product
    Fortigate-6500f-dc
    Vendor
    Fortinet
    Product
    Fortigate-6501f
    Vendor
    Fortinet
    Product
    Fortigate-6501f-dc
    Vendor
    Fortinet
    Product
    Fortigate-6601f
    Vendor
    Fortinet
    Product
    Fortigate-6601f-dc
    Vendor
    Fortinet
    Product
    Fortigate-7030e
    Vendor
    Fortinet
    Product
    Fortigate-7040e
    Vendor
    Fortinet
    Product
    Fortigate-7060e
    Vendor
    Fortinet
    Product
    Fortigate-7121f
    Vendor
    Fortinet
    Product
    Fortios
    Vendor
    Fortinet
    Product
    Fortiproxy
    Vendor
    Fortinet
    Product
    Fpm-7620e
    Vendor
    Fortinet
    Product
    Fpm-7620f
    Vendor
    Fortinet
    Product
    Fpm-7630e

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High