<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>SSH authentication bypass when RADIUS authentication is used</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-255</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2022-12-06T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2022-12-06T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2022-12-06T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Access-Challenge response from the Radius server.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiProxy 7.2 all versions are not affectedFortiProxy version 7.0.0 through 7.0.6FortiProxy version 2.0.0 through 2.0.10FortiProxy 1.2 all versionsFortiProxy 1.1 all versions are not affectedFortiOS version 7.2.0 through 7.2.1FortiOS version 7.0.0 through 7.0.7FortiOS version 6.4.0 through 6.4.9FortiOS 6.2 all versionsFortiOS 6.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiOS version 7.2.2 or abovePlease upgrade to FortiOS version 7.0.8 or abovePlease upgrade to FortiOS version 6.4.10 or abovePlease upgrade to upcoming FortiOS version 6.2.13 or abovePlease upgrade to FortiProxy version 7.0.7 or abovePlease upgrade to FortiProxy version 2.0.11 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank Egbert Nijmeijer from ICT Teamwork for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiOS" Type="Product Name">
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.1">FortiOS 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.0">FortiOS 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.7">FortiOS 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.6">FortiOS 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.5">FortiOS 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.4">FortiOS 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.3">FortiOS 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.2">FortiOS 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.1">FortiOS 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.0">FortiOS 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.9">FortiOS 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.8">FortiOS 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.7">FortiOS 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.6">FortiOS 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.5">FortiOS 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.4">FortiOS 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.3">FortiOS 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.2">FortiOS 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.1">FortiOS 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.0">FortiOS 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.12" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.12">FortiOS 6.2.12</FullProductName>
                </Branch>
                <Branch Name="6.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.11">FortiOS 6.2.11</FullProductName>
                </Branch>
                <Branch Name="6.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.10">FortiOS 6.2.10</FullProductName>
                </Branch>
                <Branch Name="6.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.9">FortiOS 6.2.9</FullProductName>
                </Branch>
                <Branch Name="6.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.8">FortiOS 6.2.8</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.7">FortiOS 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.6">FortiOS 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.5">FortiOS 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.4">FortiOS 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.3">FortiOS 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.2">FortiOS 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.1">FortiOS 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.0">FortiOS 6.2.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiProxy" Type="Product Name">
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.6">FortiProxy 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.5">FortiProxy 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.4">FortiProxy 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.3">FortiProxy 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.2">FortiProxy 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.1">FortiProxy 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-7.0.0">FortiProxy 7.0.0</FullProductName>
                </Branch>
                <Branch Name="2.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.10">FortiProxy 2.0.10</FullProductName>
                </Branch>
                <Branch Name="2.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.9">FortiProxy 2.0.9</FullProductName>
                </Branch>
                <Branch Name="2.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.8">FortiProxy 2.0.8</FullProductName>
                </Branch>
                <Branch Name="2.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.7">FortiProxy 2.0.7</FullProductName>
                </Branch>
                <Branch Name="2.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.6">FortiProxy 2.0.6</FullProductName>
                </Branch>
                <Branch Name="2.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.5">FortiProxy 2.0.5</FullProductName>
                </Branch>
                <Branch Name="2.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.4">FortiProxy 2.0.4</FullProductName>
                </Branch>
                <Branch Name="2.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.3">FortiProxy 2.0.3</FullProductName>
                </Branch>
                <Branch Name="2.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.2">FortiProxy 2.0.2</FullProductName>
                </Branch>
                <Branch Name="2.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.1">FortiProxy 2.0.1</FullProductName>
                </Branch>
                <Branch Name="2.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-2.0.0">FortiProxy 2.0.0</FullProductName>
                </Branch>
                <Branch Name="1.2.13" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.13">FortiProxy 1.2.13</FullProductName>
                </Branch>
                <Branch Name="1.2.12" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.12">FortiProxy 1.2.12</FullProductName>
                </Branch>
                <Branch Name="1.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.11">FortiProxy 1.2.11</FullProductName>
                </Branch>
                <Branch Name="1.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.10">FortiProxy 1.2.10</FullProductName>
                </Branch>
                <Branch Name="1.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.9">FortiProxy 1.2.9</FullProductName>
                </Branch>
                <Branch Name="1.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.8">FortiProxy 1.2.8</FullProductName>
                </Branch>
                <Branch Name="1.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.7">FortiProxy 1.2.7</FullProductName>
                </Branch>
                <Branch Name="1.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.6">FortiProxy 1.2.6</FullProductName>
                </Branch>
                <Branch Name="1.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.5">FortiProxy 1.2.5</FullProductName>
                </Branch>
                <Branch Name="1.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.4">FortiProxy 1.2.4</FullProductName>
                </Branch>
                <Branch Name="1.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.3">FortiProxy 1.2.3</FullProductName>
                </Branch>
                <Branch Name="1.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.2">FortiProxy 1.2.2</FullProductName>
                </Branch>
                <Branch Name="1.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.1">FortiProxy 1.2.1</FullProductName>
                </Branch>
                <Branch Name="1.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiProxy-1.2.0">FortiProxy 1.2.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>SSH authentication bypass when RADIUS authentication is used</Title>
        <cvrf:CVE>CVE-2022-35843</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiOS-7.2.1</ProductID>
                <ProductID>FortiOS-7.2.0</ProductID>
                <ProductID>FortiOS-7.0.7</ProductID>
                <ProductID>FortiOS-7.0.6</ProductID>
                <ProductID>FortiOS-7.0.5</ProductID>
                <ProductID>FortiOS-7.0.4</ProductID>
                <ProductID>FortiOS-7.0.3</ProductID>
                <ProductID>FortiOS-7.0.2</ProductID>
                <ProductID>FortiOS-7.0.1</ProductID>
                <ProductID>FortiOS-7.0.0</ProductID>
                <ProductID>FortiOS-6.4.9</ProductID>
                <ProductID>FortiOS-6.4.8</ProductID>
                <ProductID>FortiOS-6.4.7</ProductID>
                <ProductID>FortiOS-6.4.6</ProductID>
                <ProductID>FortiOS-6.4.5</ProductID>
                <ProductID>FortiOS-6.4.4</ProductID>
                <ProductID>FortiOS-6.4.3</ProductID>
                <ProductID>FortiOS-6.4.2</ProductID>
                <ProductID>FortiOS-6.4.1</ProductID>
                <ProductID>FortiOS-6.4.0</ProductID>
                <ProductID>FortiOS-6.2.12</ProductID>
                <ProductID>FortiOS-6.2.11</ProductID>
                <ProductID>FortiOS-6.2.10</ProductID>
                <ProductID>FortiOS-6.2.9</ProductID>
                <ProductID>FortiOS-6.2.8</ProductID>
                <ProductID>FortiOS-6.2.7</ProductID>
                <ProductID>FortiOS-6.2.6</ProductID>
                <ProductID>FortiOS-6.2.5</ProductID>
                <ProductID>FortiOS-6.2.4</ProductID>
                <ProductID>FortiOS-6.2.3</ProductID>
                <ProductID>FortiOS-6.2.2</ProductID>
                <ProductID>FortiOS-6.2.1</ProductID>
                <ProductID>FortiOS-6.2.0</ProductID>
                <ProductID>FortiProxy-7.0.6</ProductID>
                <ProductID>FortiProxy-7.0.5</ProductID>
                <ProductID>FortiProxy-7.0.4</ProductID>
                <ProductID>FortiProxy-7.0.3</ProductID>
                <ProductID>FortiProxy-7.0.2</ProductID>
                <ProductID>FortiProxy-7.0.1</ProductID>
                <ProductID>FortiProxy-7.0.0</ProductID>
                <ProductID>FortiProxy-2.0.10</ProductID>
                <ProductID>FortiProxy-2.0.9</ProductID>
                <ProductID>FortiProxy-2.0.8</ProductID>
                <ProductID>FortiProxy-2.0.7</ProductID>
                <ProductID>FortiProxy-2.0.6</ProductID>
                <ProductID>FortiProxy-2.0.5</ProductID>
                <ProductID>FortiProxy-2.0.4</ProductID>
                <ProductID>FortiProxy-2.0.3</ProductID>
                <ProductID>FortiProxy-2.0.2</ProductID>
                <ProductID>FortiProxy-2.0.1</ProductID>
                <ProductID>FortiProxy-2.0.0</ProductID>
                <ProductID>FortiProxy-1.2.13</ProductID>
                <ProductID>FortiProxy-1.2.12</ProductID>
                <ProductID>FortiProxy-1.2.11</ProductID>
                <ProductID>FortiProxy-1.2.10</ProductID>
                <ProductID>FortiProxy-1.2.9</ProductID>
                <ProductID>FortiProxy-1.2.8</ProductID>
                <ProductID>FortiProxy-1.2.7</ProductID>
                <ProductID>FortiProxy-1.2.6</ProductID>
                <ProductID>FortiProxy-1.2.5</ProductID>
                <ProductID>FortiProxy-1.2.4</ProductID>
                <ProductID>FortiProxy-1.2.3</ProductID>
                <ProductID>FortiProxy-1.2.2</ProductID>
                <ProductID>FortiProxy-1.2.1</ProductID>
                <ProductID>FortiProxy-1.2.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.7</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-255</URL>
                <Description>SSH authentication bypass when RADIUS authentication is used</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>