← Back to browse · API

CVE-2023-33299

Severity
CRITICAL
CVSS
9.6
EPSS
0.24296
Risk score
46.9
CISA KEV
No
PoC
No
Published
2023-06-23
Modified
2024-10-23
First seen
2026-08-07
Aliases
EUVD-2023-37462, GHSA-2J65-72JP-X2MJ
Products
Fortinet:FortiNAC 7.2.0 ≤7.2.1, Fortinet:FortiNAC 8.3.7, Fortinet:FortiNAC 8.5.0 ≤8.5.4, Fortinet:FortiNAC 8.6.0 ≤8.6.5, Fortinet:FortiNAC 8.7.0 ≤8.7.6, Fortinet:FortiNAC 8.8.0 ≤8.8.11, Fortinet:FortiNAC 9.1.0 ≤9.1.9, Fortinet:FortiNAC 9.2.0 ≤9.2.7, Fortinet:FortiNAC 9.4.0 ≤9.4.2
Sources
euvd EUVD-2023-37462

Description

A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.

References