CVE-2022-45860

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac-f:7.2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-22-464 - Vendor Advisory () https://fortiguard.com/psirt/FG-IR-22-464 - Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3

Information

Published : 2023-05-03 22:15

Updated : 2024-11-21 07:29


NVD link : CVE-2022-45860

Mitre link : CVE-2022-45860

CVE.ORG link : CVE-2022-45860


JSON object : View

Products Affected

fortinet

  • fortinac
  • fortinac-f
CWE
CWE-1390

Weak Authentication

CWE-287

Improper Authentication