PT-2022-27993 · Fortinet · Fortigate

Published

2022-12-23

·

Updated

2025-01-17

·

CVE-2022-4684

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.0
Description The issue is related to improper access control in the usememos/memos GitHub repository. There have been real-world incidents where this issue was exploited, including a leak of data from over 15,000 FortiGate devices, which included sensitive information such as VPN credentials, private keys, and configurations. This highlights the potential impact of the issue on devices that remain unpatched.
Recommendations For versions prior to 0.9.0, update to version 0.9.0 or later to resolve the issue. Additionally, administrators should reset credentials and review their setups to minimize the risk of exploitation. As a temporary workaround, consider restricting access to sensitive areas of the repository until the update is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-4684
GHSA-QR52-59R6-49F4
GO-2022-1218

Affected Products

Fortigate