An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-304 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-16 11:15
Updated : 2023-02-27 10:44
NVD link : CVE-2022-39954
Mitre link : CVE-2022-39954
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
fortinet
- fortinac-f
- fortinac