← Back to browse · API

CVE-2022-39952

Severity
CRITICAL
CVSS
9.8
EPSS
0.99809
Risk score
74.13
CISA KEV
No
PoC
No
Published
2023-02-16
Modified
2024-10-23
First seen
2026-08-07
Aliases
EUVD-2022-42396, GHSA-4WJQ-4WFF-QW9C
Products
Fortinet:FortiNAC 8.5.0 ≤8.5.4, Fortinet:FortiNAC 8.7.0 ≤8.7.6, Fortinet:FortiNAC 8.3.7, Fortinet:FortiNAC 9.1.0 ≤9.1.7, Fortinet:FortiNAC 9.2.0 ≤9.2.5, Fortinet:FortiNAC 8.8.0 ≤8.8.11, Fortinet:FortiNAC 8.6.0 ≤8.6.5, Fortinet:FortiNAC 9.4.0
Sources
euvd EUVD-2022-42396

Description

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

References