cbcvebase.
CVE-2022-39946
published 2023-06-13

CVE-2022-39946: An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions…

PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.72%
49.5th percentile
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortinac
fortinetfortinac
fortinetfortinac
fortinetfortinac
fortinetfortinac8.5.0 – 8.5.4
fortinetfortinac8.6.0 – 8.6.5
fortinetfortinac8.7.0 – 8.7.6
fortinetfortinac8.8.0 – 8.8.11
fortinetfortinac9.1.0 – 9.1.10
fortinetfortinac9.2.0 – 9.2.8
fortinetfortinac9.4.0 – 9.4.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.