CVE-2022-45857

An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-371 Vendor Advisory
Configurations

Configuration 1

cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

Information

Published : 2023-01-05 08:15

Updated : 2023-01-11 05:23


NVD link : CVE-2022-45857

Mitre link : CVE-2022-45857

Products Affected
No products.