{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2022-40679","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2022-09-14T13:17:43.617Z","datePublished":"2023-04-11T16:05:49.688Z","dateUpdated":"2024-10-23T14:30:02.463Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiDDoS","defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"5.6.0","lessThanOrEqual":"5.6.1","status":"affected"},{"versionType":"semver","version":"5.5.0","lessThanOrEqual":"5.5.1","status":"affected"},{"versionType":"semver","version":"5.4.0","lessThanOrEqual":"5.4.2","status":"affected"},{"versionType":"semver","version":"5.3.0","lessThanOrEqual":"5.3.1","status":"affected"},{"version":"5.2.0","status":"affected"},{"version":"5.1.0","status":"affected"},{"version":"5.0.0","status":"affected"},{"version":"4.7.0","status":"affected"},{"version":"4.6.0","status":"affected"},{"version":"4.5.0","status":"affected"},{"versionType":"semver","version":"4.4.0","lessThanOrEqual":"4.4.2","status":"affected"},{"versionType":"semver","version":"4.3.0","lessThanOrEqual":"4.3.2","status":"affected"},{"versionType":"semver","version":"4.2.1","lessThanOrEqual":"4.2.2","status":"affected"},{"versionType":"semver","version":"4.1.1","lessThanOrEqual":"4.1.12","status":"affected"},{"versionType":"semver","version":"4.0.0","lessThanOrEqual":"4.0.1","status":"affected"}]},{"vendor":"Fortinet","product":"FortiDDoS-F","defaultStatus":"unaffected","versions":[{"version":"6.4.0","status":"affected"},{"versionType":"semver","version":"6.3.0","lessThanOrEqual":"6.3.3","status":"affected"},{"versionType":"semver","version":"6.2.0","lessThanOrEqual":"6.2.2","status":"affected"},{"versionType":"semver","version":"6.1.0","lessThanOrEqual":"6.1.4","status":"affected"}]},{"vendor":"Fortinet","product":"FortiADC","defaultStatus":"unaffected","versions":[{"version":"7.1.0","status":"affected"},{"versionType":"semver","version":"7.0.0","lessThanOrEqual":"7.0.3","status":"affected"},{"versionType":"semver","version":"6.2.0","lessThanOrEqual":"6.2.4","status":"affected"},{"versionType":"semver","version":"6.1.0","lessThanOrEqual":"6.1.6","status":"affected"},{"versionType":"semver","version":"6.0.0","lessThanOrEqual":"6.0.4","status":"affected"},{"versionType":"semver","version":"5.4.0","lessThanOrEqual":"5.4.5","status":"affected"},{"versionType":"semver","version":"5.3.0","lessThanOrEqual":"5.3.7","status":"affected"},{"versionType":"semver","version":"5.2.0","lessThanOrEqual":"5.2.8","status":"affected"},{"versionType":"semver","version":"5.1.0","lessThanOrEqual":"5.1.7","status":"affected"},{"versionType":"semver","version":"5.0.0","lessThanOrEqual":"5.0.4","status":"affected"}]}],"descriptions":[{"lang":"en","value":"An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2023-04-11T16:05:49.688Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-78","description":"Execute unauthorized code or commands","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"}}],"solutions":[{"lang":"en","value":"Please upgrade to FortiDDoS-F version 6.4.1 or above\r\nPlease upgrade to FortiDDoS-F version 6.3.4 or above\r\nPlease upgrade to FortiDDoS-F version 6.2.3 or above\r\nPlease upgrade to FortiDDoS-F version 6.1.5 or above\n\r\nPlease upgrade to FortiDDoS version 5.7.0 or above\n\r\nPlease upgrade to FortiADC version 7.1.1 or above\r\nPlease upgrade to FortiADC version 7.0.4 or above\r\nPlease upgrade to FortiADC version 6.2.5 or above"}],"references":[{"name":"https://fortiguard.com/psirt/FG-IR-22-335","url":"https://fortiguard.com/psirt/FG-IR-22-335"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T12:21:46.383Z"},"title":"CVE Program Container","references":[{"name":"https://fortiguard.com/psirt/FG-IR-22-335","url":"https://fortiguard.com/psirt/FG-IR-22-335","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-10-23T14:11:22.289076Z","id":"CVE-2022-40679","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-23T14:30:02.463Z"}}]}}