CVE-2022-42469 is a medium-severity vulnerability affecting FortiGate versions 7.2.3 and below, and 7.0.9 and below, specifically when operating in Policy-based NGFW Mode. An authenticated SSL-VPN user can bypass security policies through bookmarks in the web portal due to a permissive input list. With a CVSS score of 4.3, this vulnerability has a low attack complexity and requires authenticated access, leading to a low impact on integrity and no impact on confidentiality or availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.11CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.2.0, < 7.2.4CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.9CPE match | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.3CPE match | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.