8.6

CVE-2022-26122

An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.

Data is provided by the National Vulnerability Database (NVD)
FortinetAntivirus Engine Version0.4.23
FortinetAntivirus Engine Version2.0.49
FortinetAntivirus Engine Version2.0.60
FortinetAntivirus Engine Version4.4.54
FortinetAntivirus Engine Version6.33
FortinetAntivirus Engine Version6.137
FortinetAntivirus Engine Version6.142
FortinetAntivirus Engine Version6.144
FortinetAntivirus Engine Version6.145
FortinetAntivirus Engine Version6.156
FortinetAntivirus Engine Version6.157
FortinetAntivirus Engine Version6.243
FortinetAntivirus Engine Version6.252
FortinetAntivirus Engine Version6.253
FortinetFortimail Version >= 6.0.0 <= 6.0.12
FortinetFortimail Version >= 6.2.0 <= 6.2.9
FortinetFortimail Version >= 6.4.0 <= 6.4.6
FortinetFortimail Version >= 7.0.0 <= 7.0.2
FortinetFortimail Version4.1.0
FortinetFortios Version >= 6.0.0 <= 6.0.15
FortinetFortios Version >= 6.2.0 <= 6.2.11
FortinetFortios Version >= 6.4.0 <= 6.4.10
FortinetFortios Version >= 7.0.0 <= 7.0.6
FortinetFortios Version7.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.304
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
psirt@fortinet.com 4.7 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.