CVE-2022-45857

An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-371 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-01-05 08:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-45857

Mitre link : CVE-2022-45857

CVE.ORG link : CVE-2022-45857


JSON object : View

Products Affected

fortinet

  • fortimanager
CWE
NVD-CWE-Other CWE-286

Incorrect User Management