CVE-2022-45860

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-464 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac-f:7.2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-03 22:15

Updated : 2023-11-07 03:54


NVD link : CVE-2022-45860

Mitre link : CVE-2022-45860

CVE.ORG link : CVE-2022-45860


JSON object : View

Products Affected

fortinet

  • fortinac-f
  • fortinac
CWE
CWE-287

Improper Authentication

CWE-1390

Weak Authentication