PT-2022-5767 · Fortinet · Fortimail+2

Published

2022-11-01

·

Updated

2022-11-04

·

CVE-2022-26122

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions FortiClient, FortiMail, and FortiOS AV engines versions 6.2.168 and below FortiClient, FortiMail, and FortiOS AV engines versions 6.4.274 and below
Description The issue is related to insufficient verification of data authenticity, which may allow an attacker to bypass the AV engine. This can be achieved by manipulating MIME attachments with junk and pad characters in base64. The vulnerability can be exploited remotely, allowing an attacker to bypass security restrictions using specially crafted MIME content with base64 encoding.
Recommendations For versions 6.2.168 and below, update to a version above 6.2.168 to resolve the issue. For versions 6.4.274 and below, update to a version above 6.4.274 to resolve the issue. As a temporary workaround, consider restricting the processing of MIME attachments with base64 encoding to minimize the risk of exploitation.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07166
CVE-2022-26122

Affected Products

Forticlient
Fortimail
Fortios