CVE-2022-39952: Critical severity fortinet fortinac vulnerability
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-39952?
CVE-2022-39952 is a vulnerability that allows an unauthenticated attacker to execute unauthorized code or commands in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, and 8.3.7.
What is the severity of CVE-2022-39952?
The severity of CVE-2022-39952 is critical with a severity value of 9.8.
How does CVE-2022-39952 affect Fortinet FortiNAC?
CVE-2022-39952 affects Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, and 8.3.7 by allowing an unauthenticated attacker to execute unauthorized code or commands.
Is authentication required to exploit CVE-2022-39952?
No, authentication is not required to exploit CVE-2022-39952.
How can I fix CVE-2022-39952?
To fix CVE-2022-39952, it is recommended to upgrade Fortinet FortiNAC to a version that is not affected by the vulnerability.