CVE Vulnerabilities

CVE-2022-45857

Incorrect User Management

Published: Jan 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.

Weakness

The product does not properly manage a user within its environment.

Affected Software

Name Vendor Start Version End Version
Fortimanager Fortinet 6.2.0 (including) 6.2.9 (excluding)
Fortimanager Fortinet 6.4.0 (including) 6.4.8 (excluding)
Fortimanager Fortinet 7.0.0 (including) 7.0.2 (excluding)

References