Fortinet Fortinac-F vulnerabilities
11 known vulnerabilities affecting fortinet/fortinac-f.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-48785MEDIUMCVSS 4.8≥ 7.2.0, < 7.2.5≥ 7.2.0, ≤ 7.2.42025-03-14
CVE-2023-48785 [MEDIUM] CWE-295 CVE-2023-48785: An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.
cvelistv5nvd
CVE-2023-22633HIGHCVSS 7.5v7.2.02023-06-13
CVE-2023-22633 [HIGH] CWE-264 CVE-2023-22633: An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0
An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attack on the device via client-secure renegotiation.
nvd
CVE-2023-22637CRITICALCVSS 9.0v7.2.02023-05-03
CVE-2023-22637 [MEDIUM] CWE-79 CVE-2023-22637: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Management would permit an authenticated attacker to trigger remote code execution via crafted l
nvd
CVE-2022-45860HIGHCVSS 7.5v7.2.02023-05-03
CVE-2022-45860 [MEDIUM] CWE-1390 CVE-2022-45860: A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 a
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
nvd
CVE-2023-26203HIGHCVSS 7.8v7.2.02023-05-03
CVE-2023-26203 [MEDIUM] CWE-798 CVE-2023-26203: A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC versio
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shell commands.
nvd
CVE-2022-43950MEDIUMCVSS 4.7v7.2.02023-05-03
CVE-2022-43950 [MEDIUM] CWE-601 CVE-2022-43950: A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions,
8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL.
nvd
CVE-2022-45859MEDIUMCVSS 4.4v7.2.02023-05-03
CVE-2022-45859 [MEDIUM] CWE-522 CVE-2022-45859: An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.
nvd
CVE-2022-43951HIGHCVSS 7.5fixed in 7.2.02023-04-11
CVE-2022-43951 [MEDIUM] CWE-200 CVE-2022-43951: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests.
nvd
CVE-2022-38375CRITICALCVSS 9.8fixed in 7.2.02023-02-16
CVE-2022-38375 [CRITICAL] CWE-285 CVE-2022-38375: An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
nvd
CVE-2022-39954CRITICALCVSS 9.1fixed in 7.2.02023-02-16
CVE-2022-39954 [HIGH] CWE-611 CVE-2022-39954: An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8
nvd
CVE-2022-40675HIGHCVSS 7.4fixed in 7.2.02023-02-16
CVE-2022-40675 [MEDIUM] CWE-310 CVE-2022-40675: Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.
Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decrypt and forge protocol communication messages.
nvd