cbcvebase.
CVE-2022-40684
published 2022-10-18

CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-11-01
Exploited in the wild
EPSS
99.98%
100.0th percentile
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios>= 7.0.0 < 7.0.77.0.7
fortinetfortios>= 7.2.0 < 7.2.27.2.2
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy>= 7.0.0 < 7.0.77.0.7
fortinetfortiswitchmanager
fortinetfortiswitchmanager
fortinetfortiswitchmanager

Detection & IOCsextracted from sources · hover to see the quote

filenameconfig.conf
filenamevpn-password.txt
filename1.py
path10.20.30.41_443
port443
port10443
  • Look for configuration files obtained by the user 'Local_Process_Access' as an IoC of CVE-2022-40684 exploitation — this is an abnormal access context indicating the auth bypass was used.
  • Detect the presence of a malicious admin account named 'fortigate-tech-support' created on FortiGate devices as an IoC of post-exploitation activity via CVE-2022-40684.
  • Validate FortiGate configuration for unauthorized changes; devices running FortiOS 7.0.0–7.0.6 or 7.2.0–7.2.1 prior to November 2022 are the confirmed vulnerable population.
  • CVE-2022-40684 exploitation is performed via specially crafted HTTP or HTTPS requests to the management interface; monitor for anomalous admin-plane HTTP/HTTPS traffic from untrusted sources.
  • Check for the two known IoCs (Local_Process_Access config access and fortigate-tech-support admin account) documented under FG-IR-22-377 when hunting for CVE-2022-40684 compromise.
  • ·The leaked FortiGate data (config.conf + vpn-password.txt) originates from exploitation of CVE-2022-40684 prior to November 2022; configs only cover FortiOS 7.0.x (up to 7.0.6) and 7.2.x (up to 7.2.1) — no 7.4 or 7.6 configs are present, confirming the older vulnerable version scope.
  • ·Devices purchased since December 2022 or devices that have only ever run FortiOS 7.2.2 or above are confirmed not impacted by CVE-2022-40684.
  • ·The vpn-password.txt files in the leak were modified by a Python script (1.py) to rename files and insert the threat actor's moniker — the underlying credential data matches the older CVE-2018-13379 (FG-IR-18-384) disclosure, not a new breach.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.