CVE-2022-38375

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-329 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-02-16 19:15

Updated : 2023-11-07 03:50


NVD link : CVE-2022-38375

Mitre link : CVE-2022-38375

CVE.ORG link : CVE-2022-38375


JSON object : View

Products Affected

fortinet

  • fortinac-f
  • fortinac
CWE
NVD-CWE-Other CWE-285

Improper Authorization