CVE-2022-39946
13.06.2023, 09:15
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attackerauthenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortinac | 8.5.0 ≤ 𝑥 ≤ 8.5.4 |
fortinet | fortinac | 8.6.0 ≤ 𝑥 ≤ 8.6.5 |
fortinet | fortinac | 8.7.0 ≤ 𝑥 ≤ 8.7.6 |
fortinet | fortinac | 8.8.0 ≤ 𝑥 ≤ 8.8.11 |
fortinet | fortinac | 9.1.0 ≤ 𝑥 ≤ 9.1.10 |
fortinet | fortinac | 9.2.0 ≤ 𝑥 ≤ 9.2.8 |
fortinet | fortinac | 9.4.0 |
fortinet | fortinac | 9.4.1 |
fortinet | fortinac | 9.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration