CVE-2022-40676
Severity
5.4MEDIUM
EPSS
0.6%
top 31.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7
Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted http requests.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
2CVEList▶
CVE-2022-40676: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9↗2023-03-07
GHSA▶
GHSA-6c4j-vvvq-q626: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9↗2023-03-07
📋Vendor Advisories
1Fortinet▶
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4...↗2023-03-07