6.5
CVSSv2

CVE-2022-22300

Published: 01/03/2022 Updated: 08/08/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 up to and including 5.6.11, FortiAnalyzer version 6.0.0 up to and including 6.0.11, FortiAnalyzer version 6.2.0 up to and including 6.2.9, FortiAnalyzer version 6.4.0 up to and including 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0 up to and including 5.6.11, FortiManager version 6.0.0 up to and including 6.0.11, FortiManager version 6.2.0 up to and including 6.2.9, FortiManager version 6.4.0 up to and including 6.4.7, FortiManager version 7.0.0 up to and including 7.0.2 allows malicious user to bypass the device policy and force the password-change action for its user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortimanager

fortinet fortianalyzer