cbcvebase.
CVE-2022-45857
published 2023-01-05

CVE-2022-45857: An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a…

PriorityP339high7.5CVSS 3.1
AVNACHPRNUIRSCCLILAH
EPSS
0.30%
22.4th percentile
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetfortigate
fortinetfortimanager
fortinetfortimanager>= 6.2.0 < 6.2.96.2.9
fortinetfortimanager6.2.0 – 6.2.8
fortinetfortimanager>= 6.4.0 < 6.4.86.4.8
fortinetfortimanager6.4.0 – 6.4.7
fortinetfortimanager>= 7.0.0 < 7.0.27.0.2
fortinetfortimanager7.0.0 – 7.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.