An authentication bypass using an alternate path or...
Critical severity
Unreviewed
Published
Oct 18, 2022
to the GitHub Advisory Database
•
Updated Feb 19, 2025
Description
Published by the National Vulnerability Database
Oct 18, 2022
Published to the GitHub Advisory Database
Oct 18, 2022
Last updated
Feb 19, 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
References