CVE-2022-39946
published 2023-06-13CVE-2022-39946: An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions…
PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.72%
49.5th percentile
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinac | — | — |
| fortinet | fortinac | — | — |
| fortinet | fortinac | — | — |
| fortinet | fortinac | — | — |
| fortinet | fortinac | 8.5.0 – 8.5.4 | — |
| fortinet | fortinac | 8.6.0 – 8.6.5 | — |
| fortinet | fortinac | 8.7.0 – 8.7.6 | — |
| fortinet | fortinac | 8.8.0 – 8.8.11 | — |
| fortinet | fortinac | 9.1.0 – 9.1.10 | — |
| fortinet | fortinac | 9.2.0 – 9.2.8 | — |
| fortinet | fortinac | 9.4.0 – 9.4.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-46mg-x8hq-xrw5: An access control vulnerability [CWE-284] in FortiNAC version 9
ghsa_unreviewed·2023-06-13
CVE-2022-39946 [HIGH] CWE-284 GHSA-46mg-x8hq-xrw5: An access control vulnerability [CWE-284] in FortiNAC version 9
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.
Fortinet
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions...
vendor_fortinet·2023-06-13·CVSS 7.6
CVE-2022-39946 [HIGH] CWE-284 An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions...
FG-IR-22-332: An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions...
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.
CVEs: CVE-2022-39946
CWEs: CWE-284
CVSS: 7.6 (high)
Affected products: FortiNAC
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-13
Published