Improper Privilege Management in Fortinet FortiNAC Affects Multiple Versions
CVE-2022-39953

7.8HIGH

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
7 March 2023

Summary

The Fortinet FortiNAC product suffers from an improper privilege management vulnerability that allows attackers to escalate privileges using specially crafted commands. This weakness is present across multiple versions, including those from 9.4 down to 8.3.7, potentially exposing systems to unauthorized access and control. Organizations using affected versions are encouraged to take immediate action to mitigate this risk.

Affected Version(s)

FortiNAC 9.4.0 <= 9.4.1

FortiNAC 9.2.0 <= 9.2.6

FortiNAC 9.1.0 <= 9.1.8

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.