CVE-2022-22300: High severity fortinet fortianalyzer vulnerability
A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22300?
CVE-2022-22300 is a vulnerability in Fortinet FortiAnalyzer that improperly handles insufficient permissions or privileges.
Which versions of Fortinet FortiAnalyzer are affected by CVE-2022-22300?
Fortinet FortiAnalyzer versions 5.6.0 through 5.6.11, 6.0.0 through 6.0.11, 6.2.0 through 6.2.9, 6.4.0 through 6.4.7, and 7.0.0 through 7.0.2 are affected by CVE-2022-22300.
What is the severity of CVE-2022-22300?
CVE-2022-22300 has a severity rating of 8.8 (high).
How does CVE-2022-22300 impact Fortinet FortiAnalyzer?
CVE-2022-22300 allows attackers to exploit insufficient permissions or privileges in Fortinet FortiAnalyzer, potentially leading to unauthorized access or unauthorized actions.
Is there a fix or patch available for CVE-2022-22300?
Yes, Fortinet has released patches to address CVE-2022-22300. It is recommended to update to the latest version of Fortinet FortiAnalyzer or apply the available patches.