Description
A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiOS version 7.2.4 or above Please upgrade to FortiOS version 7.0.11 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-45539 | A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-381 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:47:05.116Z
Reserved: 2022-10-07T14:05:36.300Z
Link: CVE-2022-42469
Updated: 2024-08-03T13:10:40.867Z
Status : Modified
Published: 2023-04-11T17:15:07.490
Modified: 2024-11-21T07:25:01.723
Link: CVE-2022-42469
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD