CVE-2006-3222 describes a vulnerability in the FTP proxy module of Fortinet FortiOS (FortiGate) versions prior to 2.80 MR12 and 3.0 MR2. This flaw allows remote attackers to bypass anti-virus scanning by utilizing the Enhanced Passive (EPSV) FTP mode. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It is a network-based attack with low complexity, requiring no authentication, and primarily impacts availability (denial of service) rather than confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code is available through Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5_0mr4CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:2.5_0mr4:*:*:*:*:*:*:* | ||
2.8_mr10CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:2.8_mr10:*:*:*:*:*:*:* | ||
2.36CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:2.36:*:*:*:*:*:*:* | ||
2.50CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:2.50:*:*:*:*:*:*:* | ||
2.50_mr5CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:2.50_mr5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.