CVE-2022-42475

Fortinet FortiOS: Heap-Based Buffer Overflow

As of , CVE-2022-42475 in Fortinet FortiOS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 13 December 2022
US federal deadline
3 January 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 7 April 2025.
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
No score that dayThe EPSS file of the day CISA listed it has no score for it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: www.fortiguard.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

CISA's description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

The CVE record's description, from fortinet

CVE published
2 January 2023
Assigned by
fortinet
CVSS
9.3 Critical (CVSS 3.1, from the CNA)
CWE-197
Numeric Truncation Error
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. CISA added it to its list of exploited vulnerabilities.
  2. The CVE record was published.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Ransomware use: Unknown to Known.

FortiOS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-13379SSL VPN Path TraversalFortinet FortiOSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2024-21762Out-of-Bound WriteFortinet FortiOSPatch this weekRansomware use; EPSS 0.830.83
CVE-2020-12812SSL VPN Improper AuthenticationFortinet FortiOSPatch this weekRansomware use0.45
CVE-2019-5591Default ConfigurationFortinet FortiOSPatch this weekRansomware use0.18
CVE-2019-6693Use of Hard-Coded CredentialsFortinet FortiOSPatch this weekRansomware use0.06
CVE-2025-68686Exposure of Sensitive Information to an Unauthorized ActorFortinet FortiOSPatch soon0.30
CVE-2022-41328Path TraversalFortinet FortiOSPatch soon0.11
CVE-2021-44168Arbitrary File DownloadFortinet FortiOSPatch soon0.01

Read further