FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching

Flags FortiOS sslvpnd activity containing known CVE-2022-42475 artifact paths from file-related events.

FreeReviewedSigma · High · v5
Product
fortios
Service
sslvpnd
Author
Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75 (SigmaHQ), DRL 1.1
Published
2024-02-08
Updated
2026-07-31
title: FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching
id: 83e495aa-d95c-4d6d-b25b-ee5cf6b2d8c2
status: test
description: This rule flags exploitation indicators for CVE-2022-42475 by matching specific file path and configuration artifact keywords observed in the sslvpnd context on FortiOS. Attackers exploiting this heap-based buffer overflow may leave behind these file or backup-related indicators, making their appearance a useful signal for compromise attempts. The detection relies on FortiOS sslvpnd telemetry that captures file creation events (or equivalent) and surfaces the referenced paths in collected logs.
references:
  - https://www.fortiguard.com/psirt/FG-IR-22-398
  - https://www.bleepingcomputer.com/news/security/fortinet-says-ssl-vpn-pre-auth-rce-bug-is-exploited-in-attacks/
  - https://www.deepwatch.com/labs/customer-advisory-fortios-ssl-vpn-vulnerability-cve-2022-42475-exploited-in-the-wild/
  - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Critical-vulnerability-Protect-against-heap-based/ta-p/239420
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-42475/fortios_sslvpnd_exploit_cve_2022_42475_exploitation_indicators.yml
author: Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75, Huntrule Team
date: 2024-02-08
tags:
  - attack.initial-access
  - cve.2022-42475
  - detection.emerging-threats
logsource:
  product: fortios
  service: sslvpnd
  definition: "Requirements: file creation events or equivalent must be collected from the FortiOS SSL-VPN appliance in order for this detection to function correctly"
detection:
  keywords:
    - /data/etc/wxd.conf
    - /data/lib/libgif.so
    - /data/lib/libips.bak
    - /data/lib/libiptcp.so
    - /data/lib/libipudp.so
    - /data/lib/libjepg.so
    - /var/.sslvpnconfigbk
  condition: keywords
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 293ccb8c-bed8-4868-8296-bef30e303b7e
    type: derived