CVE-2022-39954: XEE
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39954?
CVE-2022-39954 has a high severity rating due to its potential for remote code execution through improper XML external entity reference handling.
How do I fix CVE-2022-39954?
To fix CVE-2022-39954, update Fortinet FortiNAC to versions 9.4.2 or later, or to the latest version within the specified ranges.
What versions of Fortinet FortiNAC are affected by CVE-2022-39954?
CVE-2022-39954 affects Fortinet FortiNAC versions from 8.3.7 up to 9.4.1, and various earlier versions.
Is CVE-2022-39954 exploitable remotely?
Yes, CVE-2022-39954 is exploitable remotely if the vulnerable versions of FortiNAC are exposed to untrusted XML entities.
What should I do if I cannot update FortiNAC immediately to mitigate CVE-2022-39954?
If immediate update is not possible, review your configurations to limit exposure and monitor for unusual activity related to FortiNAC.