<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Weak authentication mechanism on device registration page</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-464</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-05-03T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-05-03T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-05-03T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A weak authentication vulnerability [CWE-1390] in FortiNAC device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            At leastFortiNAC version 9.4.0 through 9.4.2FortiNAC version 9.2.0 through 9.2.6FortiNAC 9.1 all versionsFortiNAC 8.8 all versionsFortiNAC 8.7 all versionsFortiNAC 8.6 all versions are not affectedFortiNAC 8.5 all versions are not affectedFortiNAC version 7.2.0
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiNAC version 9.4.3 or abovePlease upgrade to FortiNAC-F version 7.2.1 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank KPN for bringing this issue to our attention under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiNAC" Type="Product Name">
                <Branch Name="9.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.4.2">FortiNAC 9.4.2</FullProductName>
                </Branch>
                <Branch Name="9.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.4.1">FortiNAC 9.4.1</FullProductName>
                </Branch>
                <Branch Name="9.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.4.0">FortiNAC 9.4.0</FullProductName>
                </Branch>
                <Branch Name="9.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.6">FortiNAC 9.2.6</FullProductName>
                </Branch>
                <Branch Name="9.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.5">FortiNAC 9.2.5</FullProductName>
                </Branch>
                <Branch Name="9.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.4">FortiNAC 9.2.4</FullProductName>
                </Branch>
                <Branch Name="9.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.3">FortiNAC 9.2.3</FullProductName>
                </Branch>
                <Branch Name="9.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.2">FortiNAC 9.2.2</FullProductName>
                </Branch>
                <Branch Name="9.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.1">FortiNAC 9.2.1</FullProductName>
                </Branch>
                <Branch Name="9.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.0">FortiNAC 9.2.0</FullProductName>
                </Branch>
                <Branch Name="9.1.10" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.10">FortiNAC 9.1.10</FullProductName>
                </Branch>
                <Branch Name="9.1.9" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.9">FortiNAC 9.1.9</FullProductName>
                </Branch>
                <Branch Name="9.1.8" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.8">FortiNAC 9.1.8</FullProductName>
                </Branch>
                <Branch Name="9.1.7" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.7">FortiNAC 9.1.7</FullProductName>
                </Branch>
                <Branch Name="9.1.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.6">FortiNAC 9.1.6</FullProductName>
                </Branch>
                <Branch Name="9.1.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.5">FortiNAC 9.1.5</FullProductName>
                </Branch>
                <Branch Name="9.1.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.4">FortiNAC 9.1.4</FullProductName>
                </Branch>
                <Branch Name="9.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.3">FortiNAC 9.1.3</FullProductName>
                </Branch>
                <Branch Name="9.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.2">FortiNAC 9.1.2</FullProductName>
                </Branch>
                <Branch Name="9.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.1">FortiNAC 9.1.1</FullProductName>
                </Branch>
                <Branch Name="9.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.0">FortiNAC 9.1.0</FullProductName>
                </Branch>
                <Branch Name="8.8.11" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.11">FortiNAC 8.8.11</FullProductName>
                </Branch>
                <Branch Name="8.8.10" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.10">FortiNAC 8.8.10</FullProductName>
                </Branch>
                <Branch Name="8.8.9" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.9">FortiNAC 8.8.9</FullProductName>
                </Branch>
                <Branch Name="8.8.8" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.8">FortiNAC 8.8.8</FullProductName>
                </Branch>
                <Branch Name="8.8.7" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.7">FortiNAC 8.8.7</FullProductName>
                </Branch>
                <Branch Name="8.8.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.6">FortiNAC 8.8.6</FullProductName>
                </Branch>
                <Branch Name="8.8.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.5">FortiNAC 8.8.5</FullProductName>
                </Branch>
                <Branch Name="8.8.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.4">FortiNAC 8.8.4</FullProductName>
                </Branch>
                <Branch Name="8.8.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.3">FortiNAC 8.8.3</FullProductName>
                </Branch>
                <Branch Name="8.8.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.2">FortiNAC 8.8.2</FullProductName>
                </Branch>
                <Branch Name="8.8.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.1">FortiNAC 8.8.1</FullProductName>
                </Branch>
                <Branch Name="8.8.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.0">FortiNAC 8.8.0</FullProductName>
                </Branch>
                <Branch Name="8.7.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.6">FortiNAC 8.7.6</FullProductName>
                </Branch>
                <Branch Name="8.7.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.5">FortiNAC 8.7.5</FullProductName>
                </Branch>
                <Branch Name="8.7.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.4">FortiNAC 8.7.4</FullProductName>
                </Branch>
                <Branch Name="8.7.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.3">FortiNAC 8.7.3</FullProductName>
                </Branch>
                <Branch Name="8.7.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.2">FortiNAC 8.7.2</FullProductName>
                </Branch>
                <Branch Name="8.7.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.1">FortiNAC 8.7.1</FullProductName>
                </Branch>
                <Branch Name="8.7.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.0">FortiNAC 8.7.0</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-7.2.0">FortiNAC 7.2.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Weak authentication mechanism on device registration page</Title>
        <cvrf:CVE>CVE-2022-45860</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiNAC-9.4.2</ProductID>
                <ProductID>FortiNAC-9.4.1</ProductID>
                <ProductID>FortiNAC-9.4.0</ProductID>
                <ProductID>FortiNAC-9.2.6</ProductID>
                <ProductID>FortiNAC-9.2.5</ProductID>
                <ProductID>FortiNAC-9.2.4</ProductID>
                <ProductID>FortiNAC-9.2.3</ProductID>
                <ProductID>FortiNAC-9.2.2</ProductID>
                <ProductID>FortiNAC-9.2.1</ProductID>
                <ProductID>FortiNAC-9.2.0</ProductID>
                <ProductID>FortiNAC-9.1.10</ProductID>
                <ProductID>FortiNAC-9.1.9</ProductID>
                <ProductID>FortiNAC-9.1.8</ProductID>
                <ProductID>FortiNAC-9.1.7</ProductID>
                <ProductID>FortiNAC-9.1.6</ProductID>
                <ProductID>FortiNAC-9.1.5</ProductID>
                <ProductID>FortiNAC-9.1.4</ProductID>
                <ProductID>FortiNAC-9.1.3</ProductID>
                <ProductID>FortiNAC-9.1.2</ProductID>
                <ProductID>FortiNAC-9.1.1</ProductID>
                <ProductID>FortiNAC-9.1.0</ProductID>
                <ProductID>FortiNAC-8.8.11</ProductID>
                <ProductID>FortiNAC-8.8.10</ProductID>
                <ProductID>FortiNAC-8.8.9</ProductID>
                <ProductID>FortiNAC-8.8.8</ProductID>
                <ProductID>FortiNAC-8.8.7</ProductID>
                <ProductID>FortiNAC-8.8.6</ProductID>
                <ProductID>FortiNAC-8.8.5</ProductID>
                <ProductID>FortiNAC-8.8.4</ProductID>
                <ProductID>FortiNAC-8.8.3</ProductID>
                <ProductID>FortiNAC-8.8.2</ProductID>
                <ProductID>FortiNAC-8.8.1</ProductID>
                <ProductID>FortiNAC-8.8.0</ProductID>
                <ProductID>FortiNAC-8.7.6</ProductID>
                <ProductID>FortiNAC-8.7.5</ProductID>
                <ProductID>FortiNAC-8.7.4</ProductID>
                <ProductID>FortiNAC-8.7.3</ProductID>
                <ProductID>FortiNAC-8.7.2</ProductID>
                <ProductID>FortiNAC-8.7.1</ProductID>
                <ProductID>FortiNAC-8.7.0</ProductID>
                <ProductID>FortiNAC-7.2.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>5.0</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:X/RC:R</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-464</URL>
                <Description>Weak authentication mechanism on device registration page</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>