imPC@ndo IT

Tracker / CVE-2022-45860

CVE-2022-45860

Medium 5.3

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.

Affected products and versions

fortinet fortinac · 8.7.0 → 9.2.6
fortinet fortinac · 9.4.0 → 9.4.2
fortinet fortinac-f

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References