An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
Solution:
The product does not properly manage a user within its environment.
Link | Tags |
---|---|
https://fortiguard.com/psirt/FG-IR-22-371 | vendor advisory |