CRITICAL🇵🇱 Wersja polska

CVE-2022-39952

CVSS 9.8v3.1pub. 2023-02-16upd. 2024-11-21

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortinac

    APP
    Fortinet
    8.3.7 – 8.8.99.1.0 – 9.1.8 (excl.)9.2.0 – 9.2.6 (excl.)9.4.0 – 9.4.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-33299CRITICAL9.8PL ✓same product

Krytyczna podatność deserialization RCE w Fortinet FortiNAC

CVE-2022-38375CRITICAL9.1PL ✓same product

Nieprawidłowa autoryzacja w Fortinet FortiNAC — dostęp administracyjny bez uwierzytelnienia

CVE-2022-39946HIGH7.6same product

An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 al...

CVE-2023-22633HIGH7.5same product

An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC...

CVE-2022-40676HIGH7.5same product

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC ve...