Vulnerability record · CVE-2022-42475 · published 2 January 2023
CVE-2022-42475: FortiOS and FortiProxy SSL-VPN heap buffer overflow allows remote code execution
Fortinet · Fortios
A heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS and FortiProxy SSL-VPN component lets a remote attacker trigger memory corruption through specifically crafted requests. Because it is reachable without authentication and can lead to arbitrary code or command execution, it is a severe pre-auth flaw in internet-facing VPN infrastructure.
Description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution in internet-facing VPN appliances, with KEV listing, known ransomware use, and near-maximum EPSS.
What it is
A heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS and FortiProxy SSL-VPN component lets a remote attacker trigger memory corruption through specifically crafted requests. Because it is reachable without authentication and can lead to arbitrary code or command execution, it is a severe pre-auth flaw in internet-facing VPN infrastructure.
Impact
An unauthenticated attacker can execute arbitrary code or commands on the affected device, potentially gaining full control of the appliance and any trust relationships or credentials it holds.
Attack surface
The flaw is reached over the network through the SSL-VPN service; the CVSS vector shows no privileges required and no user interaction, so any host that can reach the SSL-VPN portal can attempt exploitation.
Exploitation
It is listed in CISA KEV with known ransomware campaign use, and EPSS is near 1.0 (0.99474, 99.9th percentile), indicating active, widespread exploitation. Vendor references are tagged Exploit and Mitigation.
What to do
- Apply the Fortinet updates specified in FG-IR-22-398 for the affected FortiOS and FortiProxy branches.
- If immediate patching is not possible, disable SSL-VPN or restrict access to trusted management networks per vendor guidance.
- Rotate credentials and certificates stored or used on affected appliances after patching, treating them as potentially compromised.
- Monitor for and investigate any signs of prior compromise, since exploitation predates the public advisory.
- Track CISA KEV remediation deadlines and confirm all internet-facing instances are updated.
Detection
- Review SSL-VPN and system logs for crashes, unexpected restarts, or anomalous process behavior on FortiGate/FortiProxy devices.
- Hunt for unusual outbound connections, new local accounts, or configuration changes on the appliance following SSL-VPN activity.
- Search for known exploitation indicators and IOCs published by Fortinet and CISA for this CVE.
- Alert on abnormal request patterns or payloads targeting the SSL-VPN endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-42475 to the Known Exploited Vulnerabilities catalog on 13 December 2022 as "Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 January 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-398 | ExploitMitigationVendor Advisory |
| https://fortiguard.com/psirt/FG-IR-22-398 | ExploitMitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42475 | US Government Resource |
Track CVE-2022-42475 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42475), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.