Fortinet FortiNAC (Network Access Control) 8.3.6

CPE Details

Fortinet FortiNAC (Network Access Control) 8.3.6
8.3.6
2019-08-26
10h50 +00:00
2019-08-26
10h50 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:fortinet:fortinac:8.3.6:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortinac

Version

8.3.6

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-26116 2022-05-11 05h20 +00:00 Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
8.8
Haute
CVE-2021-24011 2021-05-10 09h43 +00:00 A privilege escalation vulnerability in FortiNAC version below 8.8.2 may allow an admin user to escalate the privileges to root by abusing the sudo privileges.
7.2
Haute
CVE-2020-12816 2020-09-24 11h29 +00:00 An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users.
6.1
Moyen
CVE-2019-5594 2019-08-23 18h10 +00:00 An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
6.1
Moyen