PoC Archive PoC Archive

tag

SSL-VPN

  • CVE-2022-40684 network CRITICAL 9.8 KEV Ransomware EPSS 100%

    CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)

    CVE-2022-40684 is an authentication-bypass vulnerability in the web management interface of FortiOS, FortiProxy, and FortiSwitchManager that allows an unauthenticated remote attacker to access the administrative REST API. The affected firmware fails to…

    Unverified 2026-07-31
  • CVE-2024-21762 web CRITICAL 9.6 KEV Ransomware EPSS 84%

    Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)

    CVE-2024-21762 is a critical out-of-bounds write in FortiOS sslvpnd reachable through the SSL VPN web interface. A remote unauthenticated attacker can send crafted HTTP requests to corrupt memory and potentially achieve remote code execution. Public reporting…

    Patched 2026-05-16