Improper Authentication in FortiOS - CVE-2022-35843
Published: December 6, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in FortiOS SSH login component when processing authentication requests if RADIUS authentication is used. A remote attacker can bypass authentication process and login into the device via sending specially crafted Access-Challenge response from the Radius server.
Affected software
FortiProxy
How to mitigate CVE-2022-35843
FortiProxy - addressed in versions 2.0.11, 7.0.7