---
id: CVE-2022-40684
title: >-
  An authentication bypass using an alternate path or channel [CWE-288] in
  Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,
  FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and
  FortiSwitchManager version 7.2.0 …
summary: >-
  An authentication bypass using an alternate path or channel [CWE-288] in
  Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,
  FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and
  FortiSwitchManager version 7.2.0 …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
  - CWE-287
vendor: fortinet
product: fortiproxy
affected:
  - 'fortiproxy >= 7.0.0, < 7.0.7'
  - fortiproxy = 7.2.0
  - fortiswitchmanager = 7.0.0
  - fortiswitchmanager = 7.2.0
  - 'fortios >= 7.0.0, < 7.0.7'
  - 'fortios >= 7.2.0, < 7.2.2'
patched:
  - fortiproxy 7.0.7
  - fortios 7.2.2
published: '2022-10-18'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-40684'
references:
  - url: >-
      http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html
    label: psirt@fortinet.com
  - url: >-
      http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.html
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/psirt/FG-IR-22-377'
    label: psirt@fortinet.com
  - url: >-
      http://packetstormsecurity.com/files/169431/Fortinet-FortiOS-FortiProxy-FortiSwitchManager-Authentication-Bypass.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/171515/Fortinet-7.2.1-Authentication-Bypass.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://fortiguard.com/psirt/FG-IR-22-377'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40684
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99984
epssPercentile: 0.99982
kev: true
kevDateAdded: '2022-10-11'
kevDueDate: '2022-11-01'
kevRansomware: true
exploited: true
exploitAvailable: true
zeroDay: true
ingestedAt: '2026-08-06T05:56:20.520Z'
exploits:
  exploitdb: true
  github: 30
  githubRepos:
    - 'https://github.com/horizon3ai/CVE-2022-40684'
    - 'https://github.com/carlosevieira/CVE-2022-40684'
    - 'https://github.com/Filiplain/Fortinet-PoC-Auth-Bypass'
  metasploit:
    - exploit/linux/http/fortinet_authentication_bypass_cve_2022_40684
  nuclei:
    - CVE-2022-40684
  checkedAt: '2026-09-20T17:26:46.485Z'
---

## Overview

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

## Affected

- `fortiproxy >= 7.0.0, < 7.0.7`
- `fortiproxy = 7.2.0`
- `fortiswitchmanager = 7.0.0`
- `fortiswitchmanager = 7.2.0`
- `fortios >= 7.0.0, < 7.0.7`
- `fortios >= 7.2.0, < 7.2.2`

## Remediation

Upgrade past the affected range:

- `fortiproxy 7.0.7`
- `fortios 7.2.2`
