CVE-2022-26117
Summary
| CVE | CVE-2022-26117 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-18 18:15:00 UTC |
| Updated | 2023-02-16 19:28:00 UTC |
| Description | An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI. |
Risk And Classification
Problem Types: CWE-521
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | 8.3.7 | All | All | All |
| Application | Fortinet | Fortinac | 8.5.4 | All | All | All |
| Application | Fortinet | Fortinac | 8.6.0 | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fortinet FortiNAC - Unprotected MySQL root account (CVE-2022-26117) · Advisory · orangecertcc/security-research · GitHub | MISC | github.com | |
| PSIRT Advisories | FortiGuard | CONFIRM | fortiguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.