CVE-2022-40678: High severity fortinet fortinac vulnerability
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to recover user passwords.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40678?
CVE-2022-40678 is classified as a vulnerability with a high severity due to its potential for local attackers to recover user passwords.
How do I fix CVE-2022-40678?
To fix CVE-2022-40678, you should upgrade Fortinet FortiNAC to a version that is not affected by this vulnerability.
Which versions of Fortinet FortiNAC are affected by CVE-2022-40678?
CVE-2022-40678 affects FortiNAC versions 8.3.7 to 9.4.0, specifically 9.2.0 to 9.2.5, 9.1.0 to 9.1.7, 8.8.0 to 8.8.11, 8.7.0 to 8.7.6, 8.6.0 to 8.6.5, and 8.5.0 to 8.5.4.
Who can exploit CVE-2022-40678?
CVE-2022-40678 can be exploited by local attackers who have access to the database.
What type of vulnerability is CVE-2022-40678?
CVE-2022-40678 is classified as an insufficiently protected credentials vulnerability.