A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.com/psirt/FG-IR-22-280 |
History
Wed, 23 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: fortinet
Published: 2023-02-16T18:06:57.630Z
Updated: 2024-10-23T14:32:34.591Z
Reserved: 2022-09-14T13:17:43.617Z
Link: CVE-2022-40677
Vulnrichment
Updated: 2024-08-03T12:21:46.434Z
NVD
Status : Modified
Published: 2023-02-16T19:15:13.250
Modified: 2024-11-21T07:21:50.170
Link: CVE-2022-40677
Redhat
No data.