# FortiOS SSL-VPN contains a heap-based buffer overflow vulnerability (CVE-2022-42475)…

Published: 2022-12-13 · Severity: critical
Canonical: https://vorant.io/reports/11613b1b-2c1d-4d2f-8acf-2d6d37bde66d/fortios-ssl-vpn-contains-a-heap-based-buffer-overflow-vulnerability-cve-2022

> FortiOS SSL-VPN contains a heap-based buffer overflow vulnerability (CVE-2022-42475) enabling unauthenticated remote code execution; active exploitation observed.

Japan's IPA has issued an alert regarding a critical heap-based buffer overflow vulnerability in FortiOS SSL-VPN, a remote access VPN product. The vulnerability allows unauthenticated remote attackers to send crafted requests that can result in arbitrary code or command execution on affected systems. Active exploitation of this vulnerability has been confirmed in the wild, prompting urgent calls for immediate patching.

Fortinet has released updated versions to address the vulnerability, and organizations are strongly advised to apply these patches immediately. For systems that cannot be immediately updated, the vendor has provided workaround measures to mitigate the risk. IPA recommends that product users investigate their systems for potential compromise and follow the guidance provided by Fortinet.

Given the combination of no authentication requirement, remote exploitability, arbitrary code execution potential, and confirmed active exploitation, this represents a severe threat to organizations running vulnerable FortiOS SSL-VPN instances. The risk of widespread impact is high, particularly as VPN appliances are commonly exposed to the internet.

## Mentioned in this report

- Vulnerabilities: CVE-2022-42475 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20221213.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/11613b1b-2c1d-4d2f-8acf-2d6d37bde66d/fortios-ssl-vpn-contains-a-heap-based-buffer-overflow-vulnerability-cve-2022.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
