CVE Vulnerabilities

CVE-2022-39953

Improper Privilege Management

Published: Mar 07, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 through 9.1.8, FortiNAC all versions 8.8, FortiNAC all versions 8.7, FortiNAC all versions 8.6, FortiNAC all versions 8.5, FortiNAC version 8.3.7 allows attacker to escalation of privilege via specially crafted commands.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Fortinac Fortinet 8.5.0 (including) 8.5.4 (including)
Fortinac Fortinet 8.6.0 (including) 8.6.5 (including)
Fortinac Fortinet 8.7.0 (including) 8.7.6 (including)
Fortinac Fortinet 8.8.0 (including) 8.8.11 (including)
Fortinac Fortinet 9.1.0 (including) 9.1.8 (including)
Fortinac Fortinet 9.2.0 (including) 9.2.6 (including)
Fortinac Fortinet 8.3.7 (including) 8.3.7 (including)
Fortinac Fortinet 9.4.0 (including) 9.4.0 (including)
Fortinac Fortinet 9.4.1 (including) 9.4.1 (including)

Potential Mitigations

References