Insufficiently Protected Credentials in FortiNAC by Fortinet
CVE-2022-45859

3.9LOW

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
3 May 2023

Summary

An insufficiently protected credentials vulnerability exists in FortiNAC versions, allowing local attackers with system access to exploit this weakness and retrieve users' passwords. This poses a significant risk to the confidentiality of sensitive information within the affected systems. Organizations using FortiNAC should review their security posture and ensure proper credential management practices are in place to mitigate potential unauthorized access.

Affected Version(s)

FortiNAC 9.4.0 <= 9.4.1

FortiNAC 9.2.0 <= 9.2.6

FortiNAC 9.1.0 <= 9.1.8

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.