PT-2022-27993 · Fortinet · Fortigate
Published
2022-12-23
·
Updated
2025-01-17
·
CVE-2022-4684
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
usememos/memos versions prior to 0.9.0
Description
The issue is related to improper access control in the usememos/memos GitHub repository. There have been real-world incidents where this issue was exploited, including a leak of data from over 15,000 FortiGate devices, which included sensitive information such as VPN credentials, private keys, and configurations. This highlights the potential impact of the issue on devices that remain unpatched.
Recommendations
For versions prior to 0.9.0, update to version 0.9.0 or later to resolve the issue. Additionally, administrators should reset credentials and review their setups to minimize the risk of exploitation. As a temporary workaround, consider restricting access to sensitive areas of the repository until the update is applied.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortigate