Incorrect User Management
CVE-2022-45857
Summary
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
- HIGH
- ADJACENT_NETWORK
- LOW
- CHANGED
- REQUIRED
- HIGH
- LOW
- HIGH
CWE-286 - Incorrect User Management
The software does not properly manage a user within its environment.
References
Advisory Timeline
- Published