CVE-2022-45860

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-464 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac-f:7.2.0:*:*:*:*:*:*:*

History

11 May 2023, 17:48

Type Values Removed Values Added
References (MISC) https://fortiguard.com/psirt/FG-IR-22-464 - (MISC) https://fortiguard.com/psirt/FG-IR-22-464 - Vendor Advisory
First Time Fortinet fortinac
Fortinet fortinac-f
Fortinet
CPE cpe:2.3:a:fortinet:fortinac-f:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-287

03 May 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-03 22:15

Updated : 2023-12-10 15:01


NVD link : CVE-2022-45860

Mitre link : CVE-2022-45860

CVE.ORG link : CVE-2022-45860


JSON object : View

Products Affected

fortinet

  • fortinac-f
  • fortinac
CWE
CWE-287

Improper Authentication

CWE-1390