CVE-2022-40676: XSS
Published Mar 7, 2023
·Updated
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted http requests.
Affected Software
7 affected components
Fortinet FortiNAC>=8.5.0<=8.5.4
Fortinet FortiNAC>=8.6.0<=8.6.5
Fortinet FortiNAC>=8.7.0<=8.7.6
Fortinet FortiNAC>=8.8.0<=8.8.11
Fortinet FortiNAC>=9.2.0<=9.2.5
Fortinet FortiNAC=8.3.7
Fortinet FortiNAC=9.4.0
Remediation
Information
Please upgrade to FortiNAC version 9.4.1 or above
Please upgrade to FortiNAC version 9.2.6 or above
Please upgrade to FortiNAC version 9.1.9 or above
Please upgrade to FortiNAC version 7.2.0 or above
Event History
Mar 7, 2023
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Fortinet FortiNAC vulnerability?
The vulnerability ID for this Fortinet FortiNAC vulnerability is CVE-2022-40676.
2
What is the severity level of CVE-2022-40676?
The severity level of CVE-2022-40676 is high.
3
What is the affected software version range for CVE-2022-40676?
The affected software versions range from 8.3.7 to 9.4.0 of Fortinet FortiNAC.
4
What is the CWE ID for CVE-2022-40676?
The CWE ID for CVE-2022-40676 is 79.
5
How can I fix the cross-site scripting vulnerability in Fortinet FortiNAC?
To fix the cross-site scripting vulnerability in Fortinet FortiNAC, update to a version beyond the affected software versions range.