Unverified Password Change in FortiADC - CVE-2022-27484

 

Unverified Password Change in FortiADC - CVE-2022-27484

Published: August 2, 2022


Vulnerability identifier: #VU65982
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27484
CWE-ID: CWE-620
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to unverified password change in GUI interface. An attacker with access to victim's session can bypass the Old Password check in the password change form and set a new password without knowledge of the old password.


Affected software

FortiADC

How to mitigate CVE-2022-27484

Install updates from vendor's website.

FortiADC - update to 6.2.4

External References

Related Security Bulletins