CVE-2022-45859
published 2023-05-03CVE-2022-45859: An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all…
PriorityP419medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.14%
4.0th percentile
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinac | — | — |
| fortinet | fortinac | 8.7.0 – 9.1.8 | — |
| fortinet | fortinac | 8.8.0 – 8.8.11 | — |
| fortinet | fortinac | 9.1.0 – 9.1.8 | — |
| fortinet | fortinac | >= 9.2.0 < 9.2.7 | 9.2.7 |
| fortinet | fortinac | 9.2.0 – 9.2.6 | — |
| fortinet | fortinac | >= 9.4.0 < 9.4.2 | 9.4.2 |
| fortinet | fortinac | 9.4.0 – 9.4.1 | — |
| fortinet | fortinac-f | — | — |
| fortinet | fortinac-f | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and...
vendor_fortinet·2023-05-03·CVSS 4.1
CVE-2022-45859 [MEDIUM] CWE-522 An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and...
FG-IR-22-456: An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and...
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.
CVEs: CVE-2022-45859
CWEs: CWE-522
CVSS: 4.1 (medium)
Affected products: FortiNAC, FortiNac-f
GHSA
GHSA-9v39-cw8g-p5rj: An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7
ghsa_unreviewed·2023-05-04
CVE-2022-45859 [MEDIUM] CWE-522 GHSA-9v39-cw8g-p5rj: An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-03
Published