CVE-2023-48785
- EPSS 0.09%
- Veröffentlicht 14.03.2025 15:46:57
- Zuletzt bearbeitet 25.07.2025 15:08:45
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an i...
CVE-2023-22633
- EPSS 0.18%
- Veröffentlicht 13.06.2023 09:15:16
- Zuletzt bearbeitet 21.11.2024 07:45:05
An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a...
CVE-2023-26203
- EPSS 0.04%
- Veröffentlicht 03.05.2023 22:15:18
- Zuletzt bearbeitet 21.11.2024 07:50:54
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the databas...
- EPSS 0.44%
- Veröffentlicht 03.05.2023 22:15:17
- Zuletzt bearbeitet 21.11.2024 07:45:06
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in Li...
CVE-2022-45859
- EPSS 0.03%
- Veröffentlicht 03.05.2023 22:15:15
- Zuletzt bearbeitet 21.11.2024 07:29:51
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' p...
CVE-2022-45860
- EPSS 0.13%
- Veröffentlicht 03.05.2023 22:15:15
- Zuletzt bearbeitet 21.11.2024 07:29:51
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to ...
CVE-2022-43950
- EPSS 0.15%
- Veröffentlicht 03.05.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:27:24
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attack...
CVE-2022-43951
- EPSS 0.32%
- Veröffentlicht 11.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:27:24
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below may allow an unauthenticated attacker to access sensitive informati...
CVE-2022-39954
- EPSS 0.04%
- Veröffentlicht 16.02.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:18:33
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 throu...
CVE-2022-40675
- EPSS 0.23%
- Veröffentlicht 16.02.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:21:49
Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decrypt and for...