CVE-2023-26206: XSS
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26206?
CVE-2023-26206 is categorized as a high severity vulnerability due to the potential for unauthorized code execution.
How do I fix CVE-2023-26206?
To mitigate CVE-2023-26206, upgrade Fortinet FortiNAC to the latest patched version.
What software versions are affected by CVE-2023-26206?
CVE-2023-26206 affects Fortinet FortiNAC versions 7.2.0, 9.1.0 to 9.1.10, 9.2.0 to 9.2.8, and 9.4.0 to 9.4.2.
What type of vulnerability is CVE-2023-26206?
CVE-2023-26206 is a cross-site scripting (XSS) vulnerability due to improper input neutralization during web page generation.
What potential impact does CVE-2023-26206 have?
CVE-2023-26206 allows attackers to execute unauthorized code or commands, which can compromise system security.