CVE-2022-39954
published 2023-02-16CVE-2022-39954: An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC…
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.55%
42.0th percentile
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinac | — | — |
| fortinet | fortinac | — | — |
| fortinet | fortinac | 8.3.7 – 9.2.7 | — |
| fortinet | fortinac | 8.5.0 – 8.5.4 | — |
| fortinet | fortinac | 8.6.0 – 8.6.5 | — |
| fortinet | fortinac | 8.7.0 – 8.7.6 | — |
| fortinet | fortinac | 8.8.0 – 8.8.11 | — |
| fortinet | fortinac | 9.1.0 – 9.1.8 | — |
| fortinet | fortinac | 9.2.0 – 9.2.7 | — |
| fortinet | fortinac | >= 9.4.0 < 9.4.2 | 9.4.2 |
| fortinet | fortinac | 9.4.0 – 9.4.1 | — |
| fortinet | fortinac-f | < 7.2.0 | 7.2.0 |
| fortinet | fortinac-f | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC vers...
vendor_fortinet·2023-02-16·CVSS 7.3
CVE-2022-39954 [HIGH] CWE-611 An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC vers...
FG-IR-22-304: An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC vers...
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
CVEs: CVE-2022-39954
CWEs: CWE-611
CVSS: 7.3 (high)
Affected products: FortiNAC, FortiNac-f, Fortinet
GHSA
GHSA-6g49-f785-8862: An improper restriction of xml external entity reference in Fortinet FortiNAC version 9
ghsa_unreviewed·2023-02-16
CVE-2022-39954 [CRITICAL] CWE-611 GHSA-6g49-f785-8862: An improper restriction of xml external entity reference in Fortinet FortiNAC version 9
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published