CVE-2022-40679

Severity
7.8HIGH
EPSS
0.1%
top 68.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateJul 6

Description

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthor

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDfortinet/fortiddos4.0.05.7.0
NVDfortinet/fortiddos-f6.1.06.1.5+3
CVEListV5fortinet/fortiddos5.6.05.6.1+14
CVEListV5fortinet/fortiddos-f6.3.06.3.3+3
NVDfortinet/fortiadc5.0.06.2.5

🔴Vulnerability Details

2
GHSA
GHSA-fjfr-24j5-f8cq: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 52023-07-06
CVEList
CVE-2022-40679: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 52023-04-11

📋Vendor Advisories

1
Fortinet
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions...2023-04-11
CVE-2022-40679 (HIGH CVSS 7.8) | An improper neutralization of speci | cvebase.io