Fortinet FortiNAC (Network Access Control) 7.2.1

CPE Details

Fortinet FortiNAC (Network Access Control) 7.2.1
7.2.1
2023-07-01
22h28 +00:00
2023-07-21
19h54 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:fortinet:fortinac:7.2.1:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortinac

Version

7.2.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-31488 2024-05-14 16h19 +00:00 An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.
9
Critique
CVE-2023-33299 2023-06-23 07h46 +00:00 A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.
9.8
Critique
CVE-2022-26116 2022-05-11 05h20 +00:00 Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
8.8
Haute
CVE-2021-24011 2021-05-10 09h43 +00:00 A privilege escalation vulnerability in FortiNAC version below 8.8.2 may allow an admin user to escalate the privileges to root by abusing the sudo privileges.
7.2
Haute
CVE-2020-12816 2020-09-24 11h29 +00:00 An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users.
6.1
Moyen