An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortimanager | 6.4.0 | 6.4.8 |
| fortinet / fortimanager | 7.0.0 | 7.0.2 |
| fortinet / fortimanager | 6.2.0 | 6.2.9 |