Oct. 18, 2022, 2:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

cve cve-2022-40684 fortios fortiproxy fortiswitchmanager

Network Security Tools Engineer / Systems Engineer

@ Node.Digital | Arlington, Virginia, United States

Scrum Master II - Global Information Security PMO

@ Marriott International | Bethesda, MD, United States

Principle Security Incident Response Analyst

@ Oracle | United States

Cyber Network Engineer

@ Peraton | Aberdeen Proving Ground, MD, United States

Red Team Operator: Assessments & Exercises Vice President

@ JPMorgan Chase & Co. | Columbus, OH, United States

Cybersecurity Undergraduate - Internship

@ esure Group | Reigate, United Kingdom