Description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Published: 2023-01-02
Score: 9.3 Critical
EPSS: 94.0% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Please upgrade to FortiOS version 7.2.3 or above Please upgrade to FortiOS version 7.0.9 or above Please upgrade to FortiOS version 6.4.11 or above Please upgrade to FortiOS version 6.2.12 or above Please upgrade to FortiOS version 6.0.16 or above Please upgrade to upcoming FortiOS-6K7K version 7.0.8 or above Please upgrade to FortiOS-6K7K version 6.4.10 or above Please upgrade to FortiOS-6K7K version 6.2.12 or above Please upgrade to FortiOS-6K7K version 6.0.15 or above Please upgrade to FortiProxy version 7.2.2 or above Please upgrade to FortiProxy version 7.0.8 or above Please upgrade to upcoming FortiProxy version 2.0.12 or above

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Oct 2025 23:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.93141}

epss

{'score': 0.94003}


Wed, 23 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-12-13'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Fortinet Fim-7901e Fim-7904e Fim-7910e Fim-7920e Fim-7921f Fim-7941f Fortigate-6300f Fortigate-6300f-dc Fortigate-6500f Fortigate-6500f-dc Fortigate-6501f Fortigate-6501f-dc Fortigate-6601f Fortigate-6601f-dc Fortigate-7030e Fortigate-7040e Fortigate-7060e Fortigate-7121f Fortios Fortiproxy Fpm-7620e Fpm-7620f Fpm-7630e
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-10-21T23:15:29.105Z

Reserved: 2022-10-07T14:05:36.301Z

Link: CVE-2022-42475

cve-icon Vulnrichment

Updated: 2024-08-03T13:10:40.927Z

cve-icon NVD

Status : Analyzed

Published: 2023-01-02T09:15:09.490

Modified: 2025-10-24T12:54:20.620

Link: CVE-2022-42475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses