CVE Vulnerabilities

CVE-2022-38375

Published: Feb 16, 2023 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

Affected Software

Name Vendor Start Version End Version
Fortinac Fortinet 9.2.0 (including) 9.2.7 (excluding)
Fortinac Fortinet 9.4.0 (including) 9.4.2 (excluding)
Fortinac-f Fortinet * 7.2.0 (excluding)

References