An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-304 | Vendor Advisory |
https://fortiguard.com/psirt/FG-IR-22-304 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/psirt/FG-IR-22-304 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
Information
Published : 2023-02-16 19:15
Updated : 2024-11-21 07:18
NVD link : CVE-2022-39954
Mitre link : CVE-2022-39954
CVE.ORG link : CVE-2022-39954
JSON object : View
Products Affected
fortinet
- fortinac
- fortinac-f
CWE
CWE-611
Improper Restriction of XML External Entity Reference