A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-21-255 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-03-01 11:15
Updated : 2022-03-09 06:51
NVD link : CVE-2022-22300
Mitre link : CVE-2022-22300
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
fortinet
- fortianalyzer
- fortimanager