CVE-2022-45857: High severity fortinet fortimanager vulnerability
Published Jan 5, 2023
·Updated
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the superadmin account is deleted.
Affected Software
3 affected components
Fortinet FortiManager>=6.2.0<6.2.9
Fortinet FortiManager>=6.4.0<6.4.8
Fortinet FortiManager>=7.0.0<7.0.2
Remediation
Information
Please upgrade to FortiManager version 7.0.2 or above
Please upgrade to FortiManager version 6.4.8 or above
Please upgrade to FortiManager version 6.2.9 or above
Event History
Jan 5, 2023
CVE Published
via MITRE·07:37 AM
Data Sourced
via MITRE·07:37 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this FortiManager vulnerability?
The vulnerability ID for this FortiManager vulnerability is CVE-2022-45857.
2
What is the severity of CVE-2022-45857?
The severity of CVE-2022-45857 is high with a severity value of 7.5.
3
Which version of FortiManager is affected by CVE-2022-45857?
FortiManager versions 6.4.6 and below are affected by CVE-2022-45857.
4
How does CVE-2022-45857 impact user management in FortiManager?
CVE-2022-45857 allows an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
5
Where can I find more information about CVE-2022-45857?
You can find more information about CVE-2022-45857 at the FortiGuard PSIRT advisory: https://fortiguard.com/psirt/FG-IR-22-371