Tracker / CVE-2022-22303
CVE-2022-22303
Low 2.8
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.
Affected products and versions
| fortinet | fortimanager · 6.2.0 → 6.2.9 |
|---|---|
| fortinet | fortimanager · 6.4.0 → 6.4.7 |
| fortinet | fortimanager · 7.0.0 → 7.0.2 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.