CVE-2022-26116

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
fortinetfortinac
𝑥
≤ 8.3.7
fortinetfortinac
8.5.0 ≤
𝑥
≤ 8.5.2
fortinetfortinac
8.6.2 ≤
𝑥
≤ 8.6.5
fortinetfortinac
8.7.0 ≤
𝑥
≤ 8.7.6
fortinetfortinac
8.8.0 ≤
𝑥
≤ 8.8.11
fortinetfortinac
9.1.0 ≤
𝑥
≤ 9.1.5
fortinetfortinac
9.2.0 ≤
𝑥
≤ 9.2.2
fortinetfortinac
8.5.4
fortinetfortinac
8.6.0
𝑥
= Vulnerable software versions