Critical severity9.8CISA KEVNVD Advisory· Published Jan 2, 2023· Updated Jun 17, 2026
CVE-2022-42475
CVE-2022-42475
Description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Affected products
6cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.0.0,<=1.0.7
- (no CPE)range: 7.2.0
- Range: 7.2.0-7.2.1, 7.0.7 and earlier
- Range: 7.2.0-7.2.2, 7.0.0-7.0.8, 6.4.0-6.4.10, 6.2.0-6.2.11, 6.0.15 and earlier
Patches
Vulnerability mechanics
References
2- fortiguard.com/psirt/FG-IR-22-398nvdExploitMitigationVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
3- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DaySecurityWeek · Jul 28, 2026
- Operation Escaneo Signals Shift in LatAm Threat LandscapeDark Reading · Jun 18, 2026
- LATAM Infrastructure Hit by Fortinet and Ivanti ExploitsInfosecurity Magazine · Jun 18, 2026