VYPR
Medium severity4.3NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026

CVE-2022-42469

CVE-2022-42469

Description

A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.

Affected products

3
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.11
    • (no CPE)range: 7.2.0
  • Range: <=7.2.3, <=7.0.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.