CVE-2022-40678
published 2023-02-16CVE-2022-40678: An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.9th percentile
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to recover user passwords.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinac | — | — |
| fortinet | fortinac | — | — |
| fortinet | fortinac | — | — |
| fortinet | fortinac | 8.5.0 – 8.5.4 | — |
| fortinet | fortinac | 8.6.0 – 8.6.5 | — |
| fortinet | fortinac | 8.7.0 – 8.7.6 | — |
| fortinet | fortinac | 8.8.0 – 8.8.11 | — |
| fortinet | fortinac | 9.1.0 – 9.1.7 | — |
| fortinet | fortinac | 9.2.0 – 9.2.5 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8...
vendor_fortinet·2023-02-16·CVSS 7.4
CVE-2022-40678 [HIGH] CWE-522 An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8...
FG-IR-22-265: An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8...
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to recover user passwords.
CVEs: CVE-2022-40678
CWEs: CWE-522
CVSS: 7.4 (high)
Affected products: FortiNAC, Fortinet
GHSA
GHSA-7pc3-hj79-39qj: An insufficiently protected credentials in Fortinet FortiNAC versions 9
ghsa_unreviewed·2023-02-16
CVE-2022-40678 [HIGH] CWE-522 GHSA-7pc3-hj79-39qj: An insufficiently protected credentials in Fortinet FortiNAC versions 9
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to recover user passwords.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published