vulnerability

Fortinet FortiManager: CVE-2022-22303: FortiManager --- Password observed in cleartext in the config conflict file

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
Mar 1, 2022
Added
Mar 22, 2022
Modified
May 25, 2026

Description

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.

Solution

fortinet-fortimanager-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.