CVE-2022-38375

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-329 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

24 Feb 2023, 23:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Fortinet fortinac-f
Fortinet
Fortinet fortinac
CPE cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
References (MISC) https://fortiguard.com/psirt/FG-IR-22-329 - (MISC) https://fortiguard.com/psirt/FG-IR-22-329 - Vendor Advisory
CWE CWE-863

16 Feb 2023, 19:39

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-16 19:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-38375

Mitre link : CVE-2022-38375

CVE.ORG link : CVE-2022-38375


JSON object : View

Products Affected

fortinet

  • fortinac-f
  • fortinac
CWE
NVD-CWE-Other CWE-285

Improper Authorization