CVE-2022-40677: High severity fortinet fortinac vulnerability
A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet FortiNAC vulnerability?
The vulnerability ID for this Fortinet FortiNAC vulnerability is CVE-2022-40677.
What is the severity of CVE-2022-40677?
The severity of CVE-2022-40677 is high.
Which versions of Fortinet FortiNAC are affected by CVE-2022-40677?
Fortinet FortiNAC versions 8.3.7, 8.5.0 through 8.5.4, 8.6.0 through 8.6.5, 8.7.0 through 8.7.6, 8.8.0 through 8.8.11, 9.1.0 through 9.1.7, 9.2.0 through 9.2.5, and 9.4.0 are affected by CVE-2022-40677.
What is the description of CVE-2022-40677?
CVE-2022-40677 is an improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiNAC, allowing an attacker to execute unauthorized code.
How do I fix CVE-2022-40677?
To fix CVE-2022-40677, it is recommended to update Fortinet FortiNAC to a version that includes a patch addressing this vulnerability.