VORANT. Threat Intelligence Sign in Get the full feed

FortiOS SSL-VPN contains a heap-based buffer overflow vulnerability (CVE-2022-42475)…

critical vulnerability

FortiOS SSL-VPN contains a heap-based buffer overflow vulnerability (CVE-2022-42475) enabling unauthenticated remote code execution; active exploitation observed.

Japan's IPA has issued an alert regarding a critical heap-based buffer overflow vulnerability in FortiOS SSL-VPN, a remote access VPN product. The vulnerability allows unauthenticated remote attackers to send crafted requests that can result in arbitrary code or command execution on affected systems. Active exploitation of this vulnerability has been confirmed in the wild, prompting urgent calls for immediate patching.

Fortinet has released updated versions to address the vulnerability, and organizations are strongly advised to apply these patches immediately. For systems that cannot be immediately updated, the vendor has provided workaround measures to mitigate the risk. IPA recommends that product users investigate their systems for potential compromise and follow the guidance provided by Fortinet.

Given the combination of no authentication requirement, remote exploitability, arbitrary code execution potential, and confirmed active exploitation, this represents a severe threat to organizations running vulnerable FortiOS SSL-VPN instances. The risk of widespread impact is high, particularly as VPN appliances are commonly exposed to the internet.

Mentioned in this report

Vulnerabilities CVE-2022-42475KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20221213.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free