A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Project Subscriptions

Vendors Products
Fortinet Subscribe
Fim-7901e Subscribe
Fim-7904e Subscribe
Fim-7910e Subscribe
Fim-7920e Subscribe
Fim-7921f Subscribe
Fim-7941f Subscribe
Fortigate-6300f Subscribe
Fortigate-6300f-dc Subscribe
Fortigate-6500f Subscribe
Fortigate-6500f-dc Subscribe
Fortigate-6501f Subscribe
Fortigate-6501f-dc Subscribe
Fortigate-6601f Subscribe
Fortigate-6601f-dc Subscribe
Fortigate-7030e Subscribe
Fortigate-7040e Subscribe
Fortigate-7060e Subscribe
Fortigate-7121f Subscribe
Fortios Subscribe
Fortiproxy Subscribe
Fpm-7620e Subscribe
Fpm-7620f Subscribe
Fpm-7630e Subscribe
Advisories

No advisories yet.

Fixes

Solution

Please upgrade to FortiOS version 7.2.3 or above Please upgrade to FortiOS version 7.0.9 or above Please upgrade to FortiOS version 6.4.11 or above Please upgrade to FortiOS version 6.2.12 or above Please upgrade to FortiOS version 6.0.16 or above Please upgrade to upcoming FortiOS-6K7K version 7.0.8 or above Please upgrade to FortiOS-6K7K version 6.4.10 or above Please upgrade to FortiOS-6K7K version 6.2.12 or above Please upgrade to FortiOS-6K7K version 6.0.15 or above Please upgrade to FortiProxy version 7.2.2 or above Please upgrade to FortiProxy version 7.0.8 or above Please upgrade to upcoming FortiProxy version 2.0.12 or above


Workaround

No workaround given by the vendor.

History

Tue, 21 Oct 2025 23:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.93141}

epss

{'score': 0.94003}


Wed, 23 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-12-13'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-10-21T23:15:29.105Z

Reserved: 2022-10-07T14:05:36.301Z

Link: CVE-2022-42475

cve-icon Vulnrichment

Updated: 2024-08-03T13:10:40.927Z

cve-icon NVD

Status : Analyzed

Published: 2023-01-02T09:15:09.490

Modified: 2025-10-24T12:54:20.620

Link: CVE-2022-42475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses