7.2

CVE-2022-39946

An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortinac Version >= 8.5.0 <= 8.5.4
Fortinet ≫ Fortinac Version >= 8.6.0 <= 8.6.5
Fortinet ≫ Fortinac Version >= 8.7.0 <= 8.7.6
Fortinet ≫ Fortinac Version >= 8.8.0 <= 8.8.11
Fortinet ≫ Fortinac Version >= 9.1.0 <= 9.1.10
Fortinet ≫ Fortinac Version >= 9.2.0 <= 9.2.8
Fortinet ≫ Fortinac Version 9.4.0
Fortinet ≫ Fortinac Version 9.4.1
Fortinet ≫ Fortinac Version 9.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.489
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Fortinet 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.