CVE Vulnerabilities

CVE-2022-42469

Published: Apr 11, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 7.0.0 (including) 7.0.11 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.4 (excluding)

References