CVE-2022-26122

MEDIUM

FortiClient/FortiMail/FortiOS AV <6.2.168 & <6.4.274 - Auth Bypass

Title source: llm
STIX 2.1

Description

An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0012
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-345
Status published
Products (18)
fortinet/antivirus_engine 0.4.23
fortinet/antivirus_engine 2.0.49
fortinet/antivirus_engine 2.0.60
fortinet/antivirus_engine 4.4.54
fortinet/antivirus_engine 6.33
fortinet/antivirus_engine 6.137
fortinet/antivirus_engine 6.142
fortinet/antivirus_engine 6.144
fortinet/antivirus_engine 6.145
fortinet/antivirus_engine 6.156
... and 8 more
Published Nov 02, 2022
Tracked Since Feb 18, 2026