Fortinet Fortinac vulnerabilities
30 known vulnerabilities affecting fortinet/fortinac.
Total CVEs
30
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH14MEDIUM10
Vulnerabilities
Page 2 of 2
CVE-2022-45858P3HIGHCVSS 7.4≥ 8.7.0, < 9.1.0≥ 9.2.0, < 9.2.6+7 more2023-05-03
CVE-2022-45858 [HIGH] CWE-327 CVE-2022-45858: A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 a
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive information or to perform man-in-the-middle attacks.
nvd
CVE-2021-41021P4MEDIUMCVSS 6.7v8.8.0v8.8.1+10 more2021-12-08
CVE-2021-41021 [MEDIUM] CVE-2021-41021: A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may al
A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to escalate the privileges to root via the sudo command.
nvd
CVE-2023-26206P4MEDIUMCVSS 6.1≥ 9.1.0, ≤ 9.1.10≥ 9.2.0, ≤ 9.2.8+2 more2024-02-15
CVE-2023-26206 [MEDIUM] CWE-79 CVE-2023-26206: An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.
nvd
CVE-2022-40676P4MEDIUMCVSS 5.4≥ 8.5.0, ≤ 8.5.4≥ 8.6.0, ≤ 8.6.5+6 more2023-03-07
CVE-2022-40676 [MEDIUM] CWE-79 CVE-2022-40676: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted http requests.
nvd
CVE-2019-5594P4MEDIUMCVSS 6.1≥ 8.3.0, ≤ 8.3.6v8.5.02019-08-23
CVE-2019-5594 [MEDIUM] CWE-79 CVE-2019-5594: An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
nvd
CVE-2022-38376P4MEDIUMCVSS 6.1≥ 8.5.0, ≤ 8.5.4≥ 8.6.0, < 9.4.2+7 more2023-02-16
CVE-2022-38376 [MEDIUM] CWE-79 CVE-2022-38376: Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulner
Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests.
nvd
CVE-2023-22638P4MEDIUMCVSS 5.4≥ 8.5.0, ≤ 8.5.4≥ 8.6.0, ≤ 8.6.5+8 more2023-02-16
CVE-2023-22638 [MEDIUM] CWE-79 CVE-2023-22638: Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in Forti
Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests.
nvd
CVE-2020-12816P4MEDIUMCVSS 6.1fixed in 8.7.32020-09-24
CVE-2020-12816 [MEDIUM] CWE-79 CVE-2020-12816: An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authen
An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users.
nvd
CVE-2022-43950P4MEDIUMCVSS 4.7≥ 8.7.0, < 9.4.2≥ 9.4.0, ≤ 9.4.1+4 more2023-05-03
CVE-2022-43950 [MEDIUM] CWE-601 CVE-2022-43950: A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions,
8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL.
nvd
CVE-2022-45859P4MEDIUMCVSS 4.4≥ 8.7.0, ≤ 9.1.8≥ 9.2.0, < 9.2.7+5 more2023-05-03
CVE-2022-45859 [MEDIUM] CWE-522 CVE-2022-45859: An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.
nvd
← Previous2 / 2