imPC@ndo IT

Tracker / CVE-2022-39946

CVE-2022-39946

High 7.6

An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.

Affected products and versions

fortinet fortinac
fortinet fortinac · 8.5.0 → 8.5.4
fortinet fortinac · 8.6.0 → 8.6.5
fortinet fortinac · 8.7.0 → 8.7.6
fortinet fortinac · 8.8.0 → 8.8.11
fortinet fortinac · 9.1.0 → 9.1.10
fortinet fortinac · 9.2.0 → 9.2.8

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References