CVE-2022-39946: High severity fortinet fortinac vulnerability
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform unauthorized jsp calls via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39946?
CVE-2022-39946 has been assigned a moderate severity rating due to its access control vulnerability.
How do I fix CVE-2022-39946?
To fix CVE-2022-39946, update your FortiNAC installation to version 9.4.3 or later.
Which FortiNAC versions are affected by CVE-2022-39946?
CVE-2022-39946 affects FortiNAC versions 9.4.2 and below, 9.2.7 and below, and all versions of 9.1, 8.8, 8.7, 8.6, 8.5.
What type of vulnerability is CVE-2022-39946?
CVE-2022-39946 is classified as an access control vulnerability, specifically CWE-284.
Can a remote attacker exploit CVE-2022-39946?
Yes, a remote attacker authenticated on the administrative interface can exploit CVE-2022-39946 to perform unauthorized JSP calls.