CVE-2022-40676

Severity
5.4MEDIUM
EPSS
0.6%
top 31.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7

Description

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted http requests.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

CVEListV5fortinet/fortinac9.2.09.2.5+7
NVDfortinet/fortinac8.5.08.5.4+7

🔴Vulnerability Details

2
CVEList
CVE-2022-40676: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 92023-03-07
GHSA
GHSA-6c4j-vvvq-q626: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 92023-03-07

📋Vendor Advisories

1
Fortinet
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4...2023-03-07
CVE-2022-40676 (MEDIUM CVSS 5.4) | A improper neutralization of input | cvebase.io