A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
References
History

Wed, 23 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2023-02-16T18:06:55.108Z

Updated: 2024-10-23T14:32:41.984Z

Reserved: 2022-09-05T13:11:35.553Z

Link: CVE-2022-39952

cve-icon Vulnrichment

Updated: 2024-08-03T12:07:42.912Z

cve-icon NVD

Status : Modified

Published: 2023-02-16T19:15:13.060

Modified: 2023-11-07T03:50:41.250

Link: CVE-2022-39952

cve-icon Redhat

No data.