CVE-2022-45860: High severity fortinet fortinac vulnerability
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45860.
What is the severity of CVE-2022-45860?
The severity of CVE-2022-45860 is high with a severity value of 7.5.
What is the affected software of CVE-2022-45860?
The affected software of CVE-2022-45860 is FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, and 8.7 all versions.
What is the CWE of CVE-2022-45860?
The CWE of CVE-2022-45860 is CWE-287.
How can an unauthenticated attacker exploit CVE-2022-45860?
An unauthenticated attacker can exploit CVE-2022-45860 by performing password spraying attacks on the device registration page.