CVE-2022-45857

An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-371 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

History

11 Jan 2023, 17:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Fortinet
Fortinet fortimanager
CWE NVD-CWE-Other
CPE cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
References (MISC) https://fortiguard.com/psirt/FG-IR-22-371 - (MISC) https://fortiguard.com/psirt/FG-IR-22-371 - Vendor Advisory

05 Jan 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-05 08:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-45857

Mitre link : CVE-2022-45857

CVE.ORG link : CVE-2022-45857


JSON object : View

Products Affected

fortinet

  • fortimanager
CWE
NVD-CWE-Other CWE-286

Incorrect User Management