CVE-2022-39954

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
16/02/2023
Last modified:
07/11/2023

Description

An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* 8.3.7 (including) 9.2.7 (including)
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* 9.4.0 (including) 9.4.2 (excluding)
cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*:* 7.2.0 (excluding)


References to Advisories, Solutions, and Tools