>> All posts

CVE-2022-40684: Fortinet FortiOS/FortiProxy authentication bypass, actively exploited

The short version: Fortinet's FortiOS, FortiProxy, and FortiSwitchManager have an authentication-bypass flaw (CVE-2022-40684) that lets an unauthenticated attacker reach and operate the administrative interface with specially crafted requests — adding admin users, changing config, and pulling credentials. It's a 9.8, it's in CISA's KEV catalog, and it's been used in ransomware intrusions. If you run an affected build with the admin interface reachable, this is patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeCritical — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~99.98% · 99.98th percentile (2026-07-16)
In CISA KEV?Yes — remediation was due 2022-11-01
Known exploited?Yes — actively exploited; associated with ransomware campaigns
Vulnerability typeCWE-287 improper authentication → administrative-interface access without credentials
Requires authenticated session?No — pre-authentication
AffectedFortiOS 7.0.0–7.0.6 & 7.2.0–7.2.1 · FortiProxy 7.0.0–7.0.6 & 7.2.0 · FortiSwitchManager 7.0.0 & 7.2.0
Fixed inFortiOS 7.0.7 / 7.2.2 · FortiProxy 7.0.7 / 7.2.1 · FortiSwitchManager 7.0.1 / 7.2.1 (or later)

What you need to know

CVE-2022-40684 is an authentication bypass using an alternate path or channel. By sending crafted HTTP/HTTPS requests — spoofing a trusted forwarding context — an unauthenticated attacker is treated as an authenticated administrator on the management interface. From there they can perform administrative operations directly.

That's the whole problem: no credential, no chain, straight to admin.

  • It's the perimeter device. FortiGate firewalls and FortiProxy sit at the network edge. Administrative control of one means control of the thing enforcing your rules and terminating your VPN.
  • It's pre-authentication and internet-reachable. Management and SSL-VPN interfaces are routinely exposed so admins and remote users can connect.
  • It's operational, not theoretical. It's in KEV, exploitation was observed shortly after disclosure, and it's been folded into ransomware playbooks. Public exploit code exists and the attack automates.

How serious we see it

Critical — the 9.8 holds up.

Unauthenticated, network-reachable administrative access to a security appliance is top-of-queue by definition, and the in-the-wild track record removes any doubt. The bounded, reassuring part: it affects specific FortiOS/FortiProxy/FortiSwitchManager builds, the fixes have been out since 2022, and exposure is quick to determine. The catch is the familiar one — patching closes the door, but an appliance touched before you patched needs a look for added admin accounts and config changes.

Recommendations

Straight from Fortinet's advisory (FG-IR-22-377) and CISA:

  1. Patch now. Upgrade to FortiOS 7.0.7 / 7.2.2, FortiProxy 7.0.7 / 7.2.1, or FortiSwitchManager 7.0.1 / 7.2.1 (or later).
  2. If you can't patch immediately, mitigate. Disable the HTTP/HTTPS administrative interface, or restrict which hosts can reach it, per Fortinet's guidance.
  3. Hunt. Review admin logs for unexpected accounts, config changes, and logins from unfamiliar sources — Fortinet published indicators.
  4. If compromised, respond. Rotate admin credentials and any secrets the device held, and review VPN and firewall configuration for tampering.
  5. Confirm your exposure first. Verify whether you run an affected build with the management interface reachable at all.

How BreachRisk sees it

BreachRisk works from the outside in, the way an attacker does. From little more than your domain it discovers internet-facing Fortinet management and SSL-VPN interfaces, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top of your results because it's in KEV.

That continuous, attacker's-eye view is the point: when the affected appliance is already mapped and ranked, you go straight to patch-and-verify instead of starting with an inventory hunt.

References

See your cyber risk, proven.