CVE-2022-38375: Critical severity fortinet fortinac vulnerability
Published Feb 16, 2023
·Updated
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
Affected Software
3 affected components
Fortinet FortiNAC>=9.2.0<9.2.7
Fortinet FortiNAC>=9.4.0<9.4.2
Fortinet FortiNAC-F<7.2.0
Remediation
Information
Please upgrade to FortiNAC-F version 7.2.0 or above
Please upgrade to FortiNAC version 9.4.2 or above
Please upgrade to FortiNAC version 9.2.7 or above
Event History
Feb 16, 2023
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38375?
CVE-2022-38375 is an improper authorization vulnerability in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6.
2
How does CVE-2022-38375 impact Fortinet FortiNAC?
CVE-2022-38375 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
3
Which versions of Fortinet FortiNAC are affected by CVE-2022-38375?
Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 are affected by CVE-2022-38375.
4
What is the severity of CVE-2022-38375?
CVE-2022-38375 has a severity rating of 9.8 (critical).
5
How can I fix CVE-2022-38375 in Fortinet FortiNAC?
To fix CVE-2022-38375, upgrade Fortinet FortiNAC to version 9.2.7 or higher.