CVE-2022-26117

An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
fortinetfortinac
8.5.0 ≤
𝑥
≤ 8.5.2
fortinetfortinac
8.6.2 ≤
𝑥
≤ 8.6.5
fortinetfortinac
8.7.0 ≤
𝑥
≤ 8.7.6
fortinetfortinac
8.8.0 ≤
𝑥
≤ 8.8.11
fortinetfortinac
9.1.0 ≤
𝑥
< 9.1.6
fortinetfortinac
9.2.0 ≤
𝑥
< 9.2.4
fortinetfortinac
8.3.7
fortinetfortinac
8.5.4
fortinetfortinac
8.6.0
𝑥
= Vulnerable software versions