CVE-2022-45857Incorrect User Management in Fortinet Fortimanager

Severity
7.5HIGHNVD
CNA6.5
EPSS
0.2%
top 55.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 5

Description

An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:HExploitability: 1.6 | Impact: 5.3

Affected Packages2 packages

NVDfortinet/fortimanager6.2.06.2.9+2
CVEListV5fortinet/fortimanager7.0.07.0.1+2

🔴Vulnerability Details

2
CVEList
CVE-2022-45857: An incorrect user management vulnerability [CWE-286] in the FortiManager version 62023-01-05
GHSA
GHSA-694q-v8vx-rvp7: An incorrect user management vulnerability [CWE-286] in the FortiManager version 62023-01-05

📋Vendor Advisories

1
Fortinet
Incorrect user management behavior leads to passwordless admin2023-01-05
CVE-2022-45857 — Incorrect User Management in Fortinet | cvebase