Researchers release PoC for Fortinet firewall flaw, exploitation attempts mount
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-40684 | Admin-Interface Auth Bypass in Fortinet FortiOS, FortiProxy & FortiSwitchManager Fortinet's FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability (CWE-288) that lets an unauthenticated remote attacker gain access to the administrative interface. It is triggered by sending specially crafted HTTP or HTTPS requests directly to the admin interface, with no credentials or exploit code required. By bypassing authentication, an attacker can perform administrative operations on the device, such as modifying configuration or creating privileged accounts. Any organization running the affected products is exposed, particularly where the management interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 with known ransomware use, and EPSS assigns it roughly a 100% probability of exploitation within 30 days, although no public PoC is known. Do: Upgrade FortiOS, FortiProxy, and FortiSwitchManager to the fixed releases identified in Fortinet's advisory per the KEV required action. As mitigation, restrict access to the admin interface (e.g., disable WAN-facing management and use local-in policies or allow-lists for management IPs). Review admin logs and device configuration for signs of unauthorized access, such as unexpected admin accounts, added SSH keys, or config changes. | 9.8 | 100% | KEV ransomware PoC ×2 |
| massHundreds of thousands of internet-exposed Fortinet admin interfaces (~300k+ exposed FortiGate/FortiProxy management interfaces observed in public scans around… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | horizon3.ai | oted, exploitation attempts have begun surfacing. Fortinet, Horizon3.ai and Wordfence have provided indicators of compromise for th |
Full article333 words · extracted from helpnetsecurity.com · click to collapse
Horizon3.ai researchers have released a PoC exploit for CVE-2022-40684, the authentication bypass vulnerability affecting Fortinet‘s firewalls and secure web gateways, and soon after exploitation attempts started rising.
“[On Thursday], the Wordfence Threat Intelligence team began tracking exploit attempts targeting CVE-2022-40684 on our network of over 4 million protected websites,” Wordfence threat analyst Ram Gall shared.
They have recorded several exploit attempts and requests from over 20 IP addresses, but most of those were attempts to discover whether a Fortinet appliance is in place.
“However, we also found that a number of these IPs are also sending out PUT requests matching the recently released proof of concept (…) which attempts to update the public SSH key of the admin user.”
Greynoise has also been tracking CVE-2022-40684 exploit attempts, and noticed them coming from an increasing number of IP addresses.

CVE-2022-40684 exploitation
It is unknown who first discovered the existence of CVE-2022-40684, but Fortinet spotted it being exploited in the wild, created patches, and privately urged customers to implement them before going public with the information.
Horizon3.ai researchers created an exploit after analyzing the differences between the vulnerable and the patched firmware, but refrained from publishing it for a few days, to give admins time to patch or implement workarounds.
On Thursday, they released the PoC along with a post detailing what caused the bug.
Since then, others have released PoCs and, as already noted, exploitation attempts have begun surfacing.
Fortinet, Horizon3.ai and Wordfence have provided indicators of compromise for those who want to check whether their devices got popped before they managed to patch – or haven’t yet patched.
Though, as security researcher Kevin Beaumont noted, many organizations probably haven’t patched yet – but there’s a silver lining:
Yeah I have reason to believe most orgs haven’t patched. But the good news is it’s v7.x of the product vuln, and most of the boxes online haven’t reached there yet, most on EOL versions.
— Kevin Beaumont (@GossiTheDog) October 13, 2022
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/10/14/cve-2022-40684-exploitation/