CVE-2022-45857

An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-22-371 - Vendor Advisory () https://fortiguard.com/psirt/FG-IR-22-371 - Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5
Summary
  • (es) Una vulnerabilidad de administración de usuarios incorrecta [CWE-286] en el componente de creación de VDOM de FortiManager versión 6.4.6 e inferiores puede permitir que un atacante acceda a FortiGate sin contraseña a través de VDOM recién creados después de eliminar la cuenta super_admin.

Information

Published : 2023-01-05 08:15

Updated : 2024-11-21 07:29


NVD link : CVE-2022-45857

Mitre link : CVE-2022-45857

CVE.ORG link : CVE-2022-45857


JSON object : View

Products Affected

fortinet

  • fortimanager
CWE
CWE-286

Incorrect User Management

NVD-CWE-Other