A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-300 |
|
History
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published: 2023-02-16T18:06:55.108Z
Updated: 2024-10-23T14:32:41.984Z
Reserved: 2022-09-05T13:11:35.553Z
Link: CVE-2022-39952
Updated: 2024-08-03T12:07:42.912Z
Status : Modified
Published: 2023-02-16T19:15:13.060
Modified: 2024-11-21T07:18:33.040
Link: CVE-2022-39952
No data.