CVE Vulnerabilities

CVE-2022-22300

Improper Handling of Exceptional Conditions

Published: Mar 01, 2022 | Modified: Aug 08, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 5.6.0 (including) 5.6.11 (including)
Fortianalyzer Fortinet 6.0.0 (including) 6.0.11 (including)
Fortianalyzer Fortinet 6.2.0 (including) 6.2.9 (including)
Fortianalyzer Fortinet 6.4.0 (including) 6.4.7 (including)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.3 (excluding)
Fortimanager Fortinet 5.6.0 (including) 5.6.11 (including)
Fortimanager Fortinet 6.0.0 (including) 6.0.11 (including)
Fortimanager Fortinet 6.2.0 (including) 6.2.9 (including)
Fortimanager Fortinet 6.4.0 (including) 6.4.7 (including)
Fortimanager Fortinet 7.0.0 (including) 7.0.3 (excluding)

References