Vulnerabilities (CVE)

Filtered by CWE-286
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45857 1 Fortinet 1 Fortimanager 2024-11-21 N/A 6.5 MEDIUM
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
CVE-2022-35503 2024-11-21 N/A 7.5 HIGH
Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.