CVE-2022-39953

Severity
7.8HIGH
EPSS
0.1%
top 70.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7

Description

A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 through 9.1.8, FortiNAC all versions 8.8, FortiNAC all versions 8.7, FortiNAC all versions 8.6, FortiNAC all versions 8.5, FortiNAC version 8.3.7 allows attacker to escalation of privilege via specially crafted commands.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5fortinet/fortinac9.4.09.4.1+7
NVDfortinet/fortinac8.5.08.5.4+8

🔴Vulnerability Details

2
GHSA
GHSA-p6h3-h8g8-59fx: A improper privilege management in Fortinet FortiNAC version 92023-03-07
CVEList
CVE-2022-39953: A improper privilege management in Fortinet FortiNAC version 92023-03-07

📋Vendor Advisories

1
Fortinet
A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6,...2023-03-07
CVE-2022-39953 (HIGH CVSS 7.8) | A improper privilege management in | cvebase.io