The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check what Fortinet product you run (FortiOS / FortiProxy) and its exact version, then plan an immediate upgrade to a fixed release.
If you can’t upgrade right away, restrict access to SSL-VPN/FortiProxy (for example, allow only known IP addresses or limit exposure to the internet) with help from your IT provider.
Ask your IT/security person to confirm whether any systems are reachable from the internet and to monitor for signs of unusual activity on the SSL-VPN/FortiProxy services.
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
In plain language
Written by AI from the record
CVE-2022-42475 is a critical security flaw in Fortinet FortiOS and FortiProxy SSL-VPN that can let an attacker, without logging in, run code; if you use Fortinet SSL-VPN/ FortiProxy, you should act immediately.
What is it
This flaw is like a broken “locked door” in your remote access system: someone on the internet can send a specially made message, and the system can get tricked into running unintended commands. The problem is a memory overflow, meaning carefully crafted input can overwhelm how the program stores data, potentially leading to take-over of the device.
Who is affected
This matters to you if you use or run Fortinet’s SSL-VPN or FortiProxy on these products/versions: Fortinet FortiOS and Fortinet FortiProxy (including FortiOS-6K7K). It specifically affects FortiOS SSL-VPN versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier, and FortiProxy SSL-VPN versions 7.2.0 through 7.2.1 and 7.0.7 and earlier.
If you don’t use Fortinet SSL-VPN/FortiProxy, this likely doesn’t apply to your business.
How urgent is it
This is RED urgent because it’s already listed as a known exploited vulnerability (CISA KEV) and the likelihood of exploitation is extremely high. There are public exploits and detection rules available, which means attackers can act quickly, even for small organizations. Move now to reduce the risk of a remote, unauthenticated compromise.
What to do — in detail
Identify exposure
Determine which devices you run from this list: Fortinet FortiOS and Fortinet FortiProxy (including FortiOS-6K7K).
Confirm the exact SSL-VPN version on each device and whether it falls into the affected ranges:
FortiOS SSL-VPN: 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier.
FortiProxy SSL-VPN: 7.2.0 through 7.2.1, 7.0.7 and earlier.
Patch immediately
Upgrade FortiOS/FortiProxy to a version that is not in the affected ranges (use Fortinet’s recommended fixed releases for CVE-2022-42475).
If you manage multiple sites, prioritize the ones exposed to the internet first (where SSL-VPN is reachable).
If you cannot patch right away (mitigations)
Reduce internet exposure: limit who can reach SSL-VPN/FortiProxy (e.g., restrict to specific source IPs, and ensure only the necessary ports are open).
Consider temporarily disabling SSL-VPN/SSL-VPN features that rely on the vulnerable component until the device can be upgraded, if doing so won’t break critical business access.
Validate
After upgrading or changing access controls, verify from outside your network that the SSL-VPN/FortiProxy endpoints behave as expected and are no longer accepting unauthenticated attempts.
Monitor and respond
Watch the Fortinet device logs for repeated failed connection attempts, unusual request patterns, or any signs that the service behavior changed unexpectedly.
Since exploitation has been associated with ransomware in the KEV listing, increase vigilance on related systems after patching (for example, check for unexpected privilege changes, suspicious admin activity, and abnormal outbound connections).
Technical context
Severity/impact: This is a heap-based buffer overflow (CWE-122) in Fortinet FortiOS SSL-VPN and FortiProxy SSL-VPN. The issue can allow a remote, unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Affected products/versions:
FortiOS SSL-VPN: 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier.
FortiProxy SSL-VPN: 7.2.0 through 7.2.1, 7.0.7 and earlier.
Exploitation status: Press information indicates “none,” but the vulnerability is included in CISA KEV (known exploited in the wild), which means it has been observed being used by attackers. EPSS is listed as 99.5% estimated probability of exploitation in the next 30 days, and a public exploit is available; there is also a Nuclei detection template.
Attack vector: Remote unauthenticated access through crafted requests to the SSL-VPN/FortiProxy SSL-VPN service.
What EPSS/KEV mean here:
EPSS (Exploit Prediction Scoring System) is an estimate of how likely exploitation is; the provided value is extremely high.
KEV (CISA Known Exploited Vulnerabilities) indicates the vulnerability is known to be exploited in real-world attacks; this elevates urgency.
Public exploit/detection: Public exploit availability and Nuclei template presence indicate automated scanning and exploitation attempts are feasible.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.