CVE Vulnerabilities

CVE-2022-43951

Published: Apr 11, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests.

Affected Software

Name Vendor Start Version End Version
Fortinac Fortinet 8.7.0 (including) 9.2.7 (including)
Fortinac Fortinet 9.4.0 (including) 9.4.2 (excluding)
Fortinac-f Fortinet * 7.2.0 (excluding)

References