CVE-2022-22300
Last modified
CVE-2022-22300 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortianalyzer | >= 5.6.0, <= 5.6.11 |
| Fortinet | Fortianalyzer | >= 6.0.0, <= 6.0.11 |
| Fortinet | Fortianalyzer | >= 6.2.0, <= 6.2.9 |
| Fortinet | Fortianalyzer | >= 6.4.0, <= 6.4.7 |
| Fortinet | Fortianalyzer | >= 7.0.0, < 7.0.3 |
| Fortinet | Fortimanager | >= 5.6.0, <= 5.6.11 |
| Fortinet | Fortimanager | >= 6.0.0, <= 6.0.11 |
| Fortinet | Fortimanager | >= 6.2.0, <= 6.2.9 |
| Fortinet | Fortimanager | >= 6.4.0, <= 6.4.7 |
| Fortinet | Fortimanager | >= 7.0.0, < 7.0.3 |
References
- https://fortiguard.com/psirt/FG-IR-21-255Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-21-255Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22300?
How severe is CVE-2022-22300?
How do I fix CVE-2022-22300?
Are you affected by CVE-2022-22300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
