CVE-2022-22300
Published Mar 1, 2022
Last updated a year ago
Overview
- Description
- A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 through 5.6.11, FortiManager version 6.0.0 through 6.0.11, FortiManager version 6.2.0 through 6.2.9, FortiManager version 6.4.0 through 6.4.7, FortiManager version 7.0.0 through 7.0.2 allows attacker to bypass the device policy and force the password-change action for its user.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 6.4
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-755
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F405CC91-9EDE-43F4-ACB3-5744F0FAB7BF", "versionEndIncluding": "5.6.11", "versionStartIncluding": "5.6.0" }, { "criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54813EA4-11C3-430F-82AC-CBD542966E7C", "versionEndIncluding": "6.0.11", "versionStartIncluding": "6.0.0" }, { "criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "111C793F-C2E0-4042-A269-D40E1815A672", "versionEndIncluding": "6.2.9", "versionStartIncluding": "6.2.0" }, { "criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FE9C581-AB9F-4044-8C62-23B5494EFD27", "versionEndIncluding": "6.4.7", "versionStartIncluding": "6.4.0" }, { "criteria": "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F769E92C-C005-4BC8-9F48-F2E6218FFEC6", "versionEndExcluding": "7.0.3", "versionStartIncluding": "7.0.0" }, { "criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC5BB5B9-7C51-4840-9D25-DA41C0EF16C6", "versionEndIncluding": "5.6.11", "versionStartIncluding": "5.6.0" }, { "criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD729EF3-1665-4CE7-9FDD-450D5F79A2B9", "versionEndIncluding": "6.0.11", "versionStartIncluding": "6.0.0" }, { "criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D79F4BE-B6BB-414A-A132-D3650B2B5B4F", "versionEndIncluding": "6.2.9", "versionStartIncluding": "6.2.0" }, { "criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "105F23CF-6375-402E-A2ED-9827510196EA", "versionEndIncluding": "6.4.7", "versionStartIncluding": "6.4.0" }, { "criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "703550D7-5800-4870-9FE7-CE4B45B12591", "versionEndExcluding": "7.0.3", "versionStartIncluding": "7.0.0" } ], "operator": "OR" } ] } ]