Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39946


An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.


Published

2023-06-13T09:15:14.620

Last Modified

2024-11-21T07:18:32.160

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortinac ≤ 8.5.4 Yes
Application fortinet fortinac ≤ 8.6.5 Yes
Application fortinet fortinac ≤ 8.7.6 Yes
Application fortinet fortinac ≤ 8.8.11 Yes
Application fortinet fortinac ≤ 9.1.10 Yes
Application fortinet fortinac ≤ 9.2.8 Yes
Application fortinet fortinac 9.4.0 Yes
Application fortinet fortinac 9.4.1 Yes
Application fortinet fortinac 9.4.2 Yes

References