CVE Vulnerabilities

CVE-2023-22633

Published: Jun 13, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attack on the device via client-secure renegotiation.

Affected Software

Name Vendor Start Version End Version
Fortinac Fortinet 8.7.0 (including) 8.7.6 (including)
Fortinac Fortinet 8.8.0 (including) 8.8.11 (including)
Fortinac Fortinet 9.1.0 (including) 9.1.8 (including)
Fortinac Fortinet 9.2.0 (including) 9.2.6 (including)
Fortinac Fortinet 9.4.0 (including) 9.4.0 (including)
Fortinac Fortinet 9.4.1 (including) 9.4.1 (including)
Fortinac-f Fortinet 7.2.0 (including) 7.2.0 (including)

References