CVE-2022-38375
published 2023-02-16CVE-2022-38375: An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinac | — | — |
| fortinet | fortinac | >= 9.2.0 < 9.2.7 | 9.2.7 |
| fortinet | fortinac | 9.2.0 – 9.2.6 | — |
| fortinet | fortinac | >= 9.4.0 < 9.4.2 | 9.4.2 |
| fortinet | fortinac | 9.4.0 – 9.4.1 | — |
| fortinet | fortinac-f | < 7.2.0 | 7.2.0 |
| fortinet | fortinac-f | — | — |
| fortinet | fortinet | — | — |