CVE-2022-42475
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
18 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.92%
probability
This CVE has a 93.92% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroHeap buffer overflow in sslvpnd
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-197
· Numeric Truncation Error
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-681
· Incorrect Conversion between Numeric Types
CWE-704
· Incorrect Type Conversion
CWE-787
· Out-of-bounds Write
Google Project Zero
Patched
Dec. 12, 2022
Reported by
???
Root Cause Analysis
???
Exploits & PoC
scrt/cve-2022-42475
POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon
108
0xhaggis/CVE-2022-42475
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
35
P4x1s/CVE-2022-42475-RCE-POC
CVE-2022-42475 飞塔RCE漏洞 POC
8
Amir-hy/cve-2022-42475
FortiOS buffer overflow vulnerability
7
Mustafa1986/cve-2022-42475-Fortinet
PoC CVE-2022-42475 — Mustafa1986/cve-2022-42475-Fortinet
1
ArthurHendrich/CVE-2022-42475-POC
PoC CVE-2022-42475 — ArthurHendrich/CVE-2022-42475-POC
0
natceil/cve-2022-42475
PoC CVE-2022-42475 — natceil/cve-2022-42475
0
7 repos — triés par ⭐
Rechercher sur GitHub ↗
Fortinet warns of new critical FortiManager flaw used in zero-day attacks
BleepingComputer
Oct 23, 2024
Fortinet warns of new FortiWeb zero-day exploited in attacks
BleepingComputer
Nov 18, 2025
Fortinet: Govt networks targeted with now-patched SSL-VPN zero-day
BleepingComputer
Jan 12, 2023
CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
Tenable-Research
Apr 06, 2026
Fortinet: New FortiOS bug used as zero-day to attack govt networks
BleepingComputer
Mar 13, 2023
Fortinet says SSL-VPN pre-auth RCE bug is exploited in attacks
BleepingComputer
Dec 12, 2022
New Boldmove Linux malware used to backdoor Fortinet devices
BleepingComputer
Jan 20, 2023
Security Advisory 2022-086
CERT-EU
Dec 13, 2022
Signal Intelligence
Confidence
92%
EPSS
93.92%
Mentions
18
Last Seen
Apr 06, 2026
CNA Information
Analyst Note
CVE-2022-42475 is a critical heap-based buffer overflow (CVSS 9.3) affecting multiple versions of FortiOS and FortiProxy SSL-VPN with remote code execution capability, validated by inclusion in Google Project Zero's tracking and corroborated by official CERT-EU security advisory. The vulnerability affects unauthenticated attack vectors across widely-deployed enterprise security appliances, providing strong evidence for confirmed status.
Threat Actors 72
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
DarkHotel
apt_group
Information theft and espionage
🇰🇷 KR
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
FIN7
apt_group
Financial crime
🇷🇺 RU
APT32
apt_group
Information theft and espionage
🇻🇳 VN
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
Careto
apt_group
Information theft and espionage
🇪🇸 ES
Leviathan
apt_group
Information theft and espionage
🇨🇳 CN
BelialDemon
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Energetic Bear
apt_group
Information theft and espionage
🇷🇺 RU
Nitro
apt_group
Information theft and espionage
🇨🇳 CN
MAGNALLIUM
apt_group
Sabotage and destruction
🇮🇷 IR
Ice Fog
apt_group
Information theft and espionage
🇨🇳 CN
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
Kinsing
apt_group
🇷🇺 RU
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Naikon
apt_group
Information theft and espionage
🇨🇳 CN
Volt Typhoon
apt_group
Information theft and espionage
🇨🇳 CN
Wekby
apt_group
Information theft and espionage
🇨🇳 CN
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
Evilnum
apt_group
Information theft and espionage
TeamTNT
apt_group
🇩🇪 DE
ProjectSauron
apt_group
Information theft and espionage
🇺🇸 US
ArcaneDoor
apt_group
🇨🇳 CN
Predatory Sparrow
apt_group
Sabotage and destruction
🇮🇱 IL
PROMETHIUM
apt_group
Information theft and espionage
🇹🇷 TR
Silence group
apt_group
Financial crime
🇷🇺 RU
Water Gamayun
apt_group
🇷🇺 RU
APT24
apt_group
Information theft and espionage
🇨🇳 CN
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
GhostNet
apt_group
Information theft and espionage
🇨🇳 CN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Putter Panda
apt_group
Information theft and espionage
🇨🇳 CN
ShadowSyndicate
apt_group
🇷🇺 RU
NetTraveler
apt_group
Information theft and espionage
🇨🇳 CN
El Machete
apt_group
Information theft and espionage
🇻🇪 VE
UNC3886
apt_group
Information theft and espionage
🇨🇳 CN
TeamXRat
apt_group
🇧🇷 BR
IXESHE
apt_group
Information theft and espionage
🇨🇳 CN
Anchor Panda
apt_group
Information theft and espionage
🇨🇳 CN
GCMAN
apt_group
Financial crime
🇷🇺 RU
PowerPool
apt_group
Information theft and espionage
🇷🇺 RU
Blue Termite
apt_group
Information theft and espionage
🇨🇳 CN
Blackgear
apt_group
Information theft and espionage
🇨🇳 CN
GC01
apt_group
Financial gain
🇨🇦 CA
Rocke
apt_group
🇨🇳 CN
RedAlpha
apt_group
Information theft and espionage
🇨🇳 CN
Markopolo
apt_group
🇷🇺 RU
Mora_001
apt_group
🇷🇺 RU
Red October
apt_group
🇷🇺 RU
Scarab
apt_group
Information theft and espionage
🇨🇳 CN
ZooPark
apt_group
Information theft and espionage
🇮🇷 IR
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Test Panda
apt_group
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Iron Group
apt_group
Information theft and espionage
🇨🇳 CN
puNK-003
apt_group
🇰🇵 KP
Operation Shadow Force
apt_group
🇨🇳 CN
Big Panda
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Electric Panda
apt_group
🇨🇳 CN
Dark Partners
apt_group
Triage Info
Decided atMar 03, 2026