Evidence dossier

CVE-2022-42475

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier…

Exploited in the wild (CISA KEV since Dec 13, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 99.5% exploit likelihood as of Jul 18, 2026.

88.090.2Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

State
PUBLISHED
Published
Jan 2, 2023
Updated
Oct 21, 2025
Evidence coverage
98%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    fortinet

    Record text: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

    Inspect raw assertion
    Field
    container
    Value
    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.47% probability · 99.94th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.994740000000; percentile 0.999400000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Dec 13, 2022 · first observed Jul 19, 2026

Exploit likelihood99.47%

FIRST EPSS · score date Jul 18, 2026 · 99.9th percentile · first observed Jul 19, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
fortinetOriginal assertion
Record text

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Inspect raw assertion
Field
container
Value
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.47% probability · 99.94th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.994740000000; percentile 0.999400000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
40Underlying assertions
23Canonical products
19Target assertions
21Constraint assertions

Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

25 scope groups

fortinet · source assertedFortinetFortiOSDirect source scope
Affected: 7.2.0 through 7.2.2 (semver comparison)Affected: 7.0.0 through 7.0.8 (semver comparison)Affected: 6.4.0 through 6.4.10 (semver comparison)Affected: 6.2.0 through 6.2.11 (semver comparison)Affected: 6.0.0 through 6.0.15 (semver comparison)Affected: 5.6.0 through 5.6.14 (semver comparison)Affected: 5.4.0 through 5.4.13 (semver comparison)Affected: 5.2.0 through 5.2.15 (semver comparison)Affected: 5.0.0 through 5.0.14 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "7.2.0", "versionType": "semver", "lessThanOrEqual": "7.2.2"}, {"status": "affected", "version": "7.0.0", "versionType": "semver", "lessThanOrEqual": "7.0.8"}, {"status": "affected", "version": "6.4.0", "versionType": "semver", "lessThanOrEqual": "6.4.10"}, {"status": "affected", "version": "6.2.0", "versionType": "semver", "lessThanOrEqual": "6.2.11"}, {"status": "affected", "version": "6.0.0", "versionType": "semver", "lessThanOrEqual": "6.0.15"}, {"status": "affected", "version": "5.6.0", "versionType": "semver", "lessThanOrEqual": "5.6.14"}, {"status": "affected", "version": "5.4.0", "versionType": "semver", "lessThanOrEqual": "5.4.13"}, {"status": "affected", "version": "5.2.0", "versionType": "semver", "lessThanOrEqual": "5.2.15"}, {"status": "affected", "version": "5.0.0", "versionType": "semver", "lessThanOrEqual": "5.0.14"}]
fortinet · source assertedFortinetFortiProxyDirect source scope
Affected: 7.2.0 through 7.2.1 (semver comparison)Affected: 7.0.0 through 7.0.7 (semver comparison)Affected: 2.0.0 through 2.0.11 (semver comparison)Affected: 1.2.0 through 1.2.13 (semver comparison)Affected: 1.1.0 through 1.1.6 (semver comparison)Affected: 1.0.0 through 1.0.7 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "7.2.0", "versionType": "semver", "lessThanOrEqual": "7.2.1"}, {"status": "affected", "version": "7.0.0", "versionType": "semver", "lessThanOrEqual": "7.0.7"}, {"status": "affected", "version": "2.0.0", "versionType": "semver", "lessThanOrEqual": "2.0.11"}, {"status": "affected", "version": "1.2.0", "versionType": "semver", "lessThanOrEqual": "1.2.13"}, {"status": "affected", "version": "1.1.0", "versionType": "semver", "lessThanOrEqual": "1.1.6"}, {"status": "affected", "version": "1.0.0", "versionType": "semver", "lessThanOrEqual": "1.0.7"}]
NVD CPE · HARDWAREfortinetfim-7901eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cac87e66d999c0f752d8ba0608145ceb3efce175b3900ddb13bb47558914b9ddLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fim-7901e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    689b8a1f-112d-42ce-a29b-692ef00150ad
NVD CPE · HARDWAREfortinetfim-7904eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-1b7a6bcad2c4a45f10b28353d23fb039c8494f639c9a791c4607ca4f1006748dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fim-7904e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    33603726-ab6b-4773-904e-de103cdcea70
NVD CPE · HARDWAREfortinetfim-7910eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-c2ac60f3925924b411296a8d49f48d72fee925cefd4d5acdc8ed308cc2810507Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fim-7910e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db6056ee-e76c-4064-b252-e0d65a1cbfbb
NVD CPE · HARDWAREfortinetfim-7920eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-93d35c1f8f5ff6c42927382de35cce3b368bd99334d2992896f0fa89d8655bedLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fim-7920e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    43df83ac-1b86-4c45-b5a3-ef56b65c9bf7
NVD CPE · HARDWAREfortinetfim-7921fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-83c371503e5eedbe35d2f6576b8f74c24a20a38837fe167e731f2bcf2f88c495Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fim-7921f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7bad653-d841-4744-ae85-c24fc1f3f6df
NVD CPE · HARDWAREfortinetfim-7941fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-92973d74d7bcbf1aa0f7315f014c4b6e41351d1f82b3dd1a1c61d5a0518279aaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fim-7941f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8adcb4f1-e237-4525-95c4-2c8efdd7a109
NVD CPE · HARDWAREfortinetfortigate-6300fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ea144090f9ac5a0af94ea3a5cafedb81a3083cb17231a3eeec24323e359a68eeLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6300f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb61396b-d9ef-44de-b211-e92ef5a52888
NVD CPE · HARDWAREfortinetfortigate-6300f-dcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-f81765840a2a5c97de6d118e51e3e7a6bb242b03523c63f3fd4698a7fc551b6bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6300f-dc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ad28c00-00cc-433f-bd7b-ac58254e4785
NVD CPE · HARDWAREfortinetfortigate-6500fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-77c62cd8b20596003bf248440ff9d88b3305535eaf25321411a860932c7193cdLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6500f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a72901a-ea5b-48b0-9d0b-a8cd8903413c
NVD CPE · HARDWAREfortinetfortigate-6500f-dcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-91c70e338516bc942f677fe542e0e591d5e871c08b07c4431e715183093b9d74Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6500f-dc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d56b4c97-9bc9-4fb9-9623-f2897050fe8b
NVD CPE · HARDWAREfortinetfortigate-6501fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-859b4f929f2a2706b6e8734c4f69eb6fda4b0db1d70cf4717a7b212e0033b0dfLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6501f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    50efcc23-1135-4bc9-b180-e9045030c844
NVD CPE · HARDWAREfortinetfortigate-6501f-dcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-975cbabb07f31a26c5cacc082ca0c4702666c83e5109fdbcf8202901f18d1dc3Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6501f-dc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1e355c55-4caa-4875-95f6-fcf3d360039f
NVD CPE · HARDWAREfortinetfortigate-6601fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-fad189cda42b7a69eaba8a01c008ca1b34a255ffd55ddc2f1c11899bb5fa3bbaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6601f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    acbfbddc-1bd8-48aa-85a3-aa727c466c8d
NVD CPE · HARDWAREfortinetfortigate-6601f-dcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-6accdd345f2cdc1c9250c4fc56d10c28c6a09de0eead6b46284e8ca1a6af17d1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-6601f-dc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a56f4f2d-be9b-458c-b906-017d14deabba
NVD CPE · HARDWAREfortinetfortigate-7030eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-8e51c0981aed04e4306355acc6c11a977bd1dbaf3252f32f4faf0e8abb258912Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-7030e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    deadc8c2-1db4-4cb9-a014-7ef279c03c08
NVD CPE · HARDWAREfortinetfortigate-7040eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-84222558941c2785d718192919ab91a221ecd031401cd011842ac7a1bb4cfd9aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-7040e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a6bbd9d7-5f9b-4438-91f9-eb496c8186c5
NVD CPE · HARDWAREfortinetfortigate-7060eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-4b6d93f2430ff4e1b66b39659e75369f6bb5dcd8bdcc0062f3f00e418d0c2041Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-7060e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    187aaef7-3fbf-488c-9935-2fa15d131228
NVD CPE · HARDWAREfortinetfortigate-7121fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5db56a8d8d4de09872b20c57c373e3c5b96927a4c27cc7b3ea9ef90929ed96afLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fortigate-7121f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d9294854-fc23-4682-a695-325ca3347f37
NVD CPE · OPERATING SYSTEMfortinetfortiosVulnerable target · 13 assertions
Any version (unconstrained) (>= 5.0.0, <= 5.0.14); Any version (unconstrained) (>= 5.2.0, <= 5.2.15); Any version (unconstrained) (>= 5.4.0, <= 5.4.13); Any version (unconstrained) (>= 5.6.0, <= 5.6.14); Any version (unconstrained) (>= 6.0.0, < 6.0.15); Any version (unconstrained) (>= 6.0.0, < 6.0.16); Any version (unconstrained) (>= 6.2.0, < 6.2.12); Any version (unconstrained) (>= 6.4.0, < 6.4.10); Any version (unconstrained) (>= 6.4.0, < 6.4.11); Any version (unconstrained) (>= 7.0.0, < 7.0.8); Any version (unconstrained) (>= 7.0.0, < 7.0.9); Any version (unconstrained) (>= 7.2.0, < 7.2.3)Canonical identity product-d06140244cc5e972beb67f7de823109a7332f0ff670c2c5c21938de936e3f496Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 6.2.0; through excluding 6.2.12
    Match ID
    f6785608-14a0-4825-bec0-899e55a9fdf1
  2. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 6.2.0; through excluding 6.2.12
    Match ID
    f6785608-14a0-4825-bec0-899e55a9fdf1
  3. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 6.0.0; through excluding 6.0.16
    Match ID
    795298d3-0c06-471c-87e2-2d04ac190ead
  4. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 6.0.0; through excluding 6.0.15
    Match ID
    77974073-d92d-4eb8-854f-a6dccd13c868
  5. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 5.2.0; through including 5.2.15
    Match ID
    3f93f9c8-6064-4ced-88df-3580c517ab51
  6. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 7.0.0; through excluding 7.0.8
    Match ID
    ee6d1d19-1227-42be-87a7-e798d60059a5
  7. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    from including 7.2.0; through excluding 7.2.3
    Match ID
    00e89c95-e9fb-473a-beb0-fa8e7225ac55
  8. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 5.4.0; through including 5.4.13
    Match ID
    0507f264-9e8d-4f9d-ab18-0c6ca5bd69f0
  9. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 5.0.0; through including 5.0.14
    Match ID
    5bb7e21e-a68b-44fc-8f0e-ef5926186f26
  10. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 6.4.0; through excluding 6.4.11
    Match ID
    55e67ef5-6af0-410a-bde7-cf745ed97328
  11. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 5.6.0; through including 5.6.14
    Match ID
    ac0afbc1-5c11-412e-9979-af89dd26efcd
  12. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 6.4.0; through excluding 6.4.10
    Match ID
    6a7730e2-63ad-48f2-ae0a-6c8c9369a734
  13. cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    from including 7.0.0; through excluding 7.0.9
    Match ID
    c424900b-9a5e-440c-996b-2cf426f2caa3
NVD CPE · APPLICATIONfortinetfortiproxyVulnerable target · 6 assertions
Any version (unconstrained) (>= 1.0.0, <= 1.0.7); Any version (unconstrained) (>= 1.1.0, <= 1.1.6); Any version (unconstrained) (>= 1.2.0, <= 1.2.13); Any version (unconstrained) (>= 2.0.0, < 2.0.12); Any version (unconstrained) (>= 7.0.0, < 7.0.8); Any version (unconstrained) (>= 7.2.0, < 7.2.2)Canonical identity product-53e2c632c140b04469e646fdc096d80536975303740dc515e32352dc87ed2607Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 7.2.0; through excluding 7.2.2
    Match ID
    f5b24750-4a57-4f80-aae8-8ac316b376c2
  2. cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 2.0.0; through excluding 2.0.12
    Match ID
    954674e3-7e54-4d94-80de-cb73ae0452ea
  3. cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 1.2.0; through including 1.2.13
    Match ID
    33b84d9a-55e3-4146-a55a-acb507e61b05
  4. cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 1.1.0; through including 1.1.6
    Match ID
    e6bbf05f-4967-4a2e-a8f8-c2086097148b
  5. cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 7.0.0; through excluding 7.0.8
    Match ID
    81e60913-fbe9-467b-ab4b-ca85e97527ba
  6. cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 1.0.0; through including 1.0.7
    Match ID
    22936f53-4480-4011-9211-174d1c507e87
NVD CPE · HARDWAREfortinetfpm-7620eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-053aa63af3b0ae442ffc52936f305a190f812dd74eac49b7640c7f1f43f7fdb5Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fpm-7620e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cafabb00-194b-41e4-940c-a5cf3a9ceceb
NVD CPE · HARDWAREfortinetfpm-7620fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-caefa0b736950e5e2d7bd7b7fe44e2e28b3b3d1611354a56ce294a383da3572cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fpm-7620f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2cc0365-4336-4700-9a29-1aea0ca781af
NVD CPE · HARDWAREfortinetfpm-7630eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-2929b3ec1a04fa8eca3f805a7dce68d81687d9f7635305376adc920832cd394dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:fortinet:fpm-7630e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7e4f7f8-50e4-4774-b1e7-13dc1a289104

Affected-product evidence

Accepted scope and product mapping

2 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-a82aadab6a309189375ddbea412e10a6aef0b5411f0ae9526eeafad0e62c10e6 · product-53e2c632c140b04469e646fdc096d80536975303740dc515e32352dc87ed2607

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
05b563b4-9da9-40a5-8930-8e42b47ba0fb3ce1dbeb-ede3-45f7-9515-f2d0b8e2dc7a42282ae4-d89b-4df4-9fba-a6323fd5d4aea3ea3732-efcf-4370-b982-d547f395c6d5ceae12db-86d3-45a7-877f-5e8603ae9fcffbcea5c6-7967-462f-9b49-2e0140dd8fd2
Mapping establishedEvidence supported

vendor-a82aadab6a309189375ddbea412e10a6aef0b5411f0ae9526eeafad0e62c10e6 · product-d06140244cc5e972beb67f7de823109a7332f0ff670c2c5c21938de936e3f496

Source class
Nvd cpe vulnerable target
Assertions
13
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
015bd763-cabe-4e4e-b617-6fd4ff410a930ccb3d56-7ca1-46a2-becd-cdd7eb00d8a51bf1d38c-1399-4463-bda7-adfde1b42e46204c88e3-096d-4e48-a758-eb68dc16d2024861435a-0e65-46b1-8570-96c0c564418b4a45f5f1-ad5b-4510-b5d8-d36401815d4f6fb43427-9d8e-4f06-99a0-37776ec2cd0273ea53b9-2707-40e3-96bf-f48382e4eaef764ef286-d835-4f52-ae47-78540592751cd4c9f149-a3fa-4e6a-9d62-e3b19c1c89e3e470828b-ec79-4044-ba1e-500b332fa851f374ebca-a931-4573-bd1d-7e6d8f19b29ff881ea56-5580-47fd-8e02-be22aed1cdd0
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1701b49e-dc83-4011-9213-b2ea849157aeeeb9d381-cb41-4a41-9023-f11c18d03af3

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
psirt@fortinet.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
fortinetCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C

Direct CVE/CNA normalized decisions

9.3Display only

fortinet

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
Validation
Base mismatch
Recomputed
9.8
Decision reason
Outside current scoring policy
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.