An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortimanager | Fortinet | 6.2.0 (including) | 6.2.9 (excluding) |
Fortimanager | Fortinet | 6.4.0 (including) | 6.4.8 (excluding) |
Fortimanager | Fortinet | 7.0.0 (including) | 7.0.2 (excluding) |