Sensitive System Information Exposure in FortiManager by Fortinet
CVE-2022-22303

2.8LOW

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
2 March 2022

Summary

The FortiManager product by Fortinet has a vulnerability that allows low privileged authenticated users to access sensitive credentials of FortiGate users by exploiting the configuration conflict files. This can lead to unauthorized access and manipulation of critical system information, highlighting the need for prompt updates to affected versions, namely FortiManager prior to versions 7.0.2, 6.4.7, and 6.2.9.

Affected Version(s)

Fortinet FortiManager FortiManager 7.0.2, 7.0.1, 7.0.0, 6.4.7, 6.4.6, 6.4.5, 6.4.4, 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.9, 6.2.8, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.