improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.
| Link | Resource |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-255 | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-21-255 | Vendor Advisory |
Configuration 1 (hide)
|
21 Nov 2024, 06:46
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 4.3 |
| References | () https://fortiguard.com/psirt/FG-IR-21-255 - Vendor Advisory |
Published : 2022-03-01 19:15
Updated : 2024-11-21 06:46
NVD link : CVE-2022-22300
Mitre link : CVE-2022-22300
CVE.ORG link : CVE-2022-22300
JSON object : View
Improper Handling of Exceptional Conditions