Configuration File Vulnerability in FortiNAC by Fortinet
CVE-2022-26117
8.8HIGH
What is CVE-2022-26117?
An empty password configuration flaw in various versions of FortiNAC allows authenticated attackers to exploit the vulnerability, potentially gaining unauthorized access to MySQL databases through the command-line interface (CLI). This issue affects multiple versions, and its presence emphasizes the importance of secure configuration practices.
Affected Version(s)
Fortinet FortiNAC FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below.