📦 Fortinac

by Fortinet

🔍 What is Fortinac?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33299

CRITICAL CVSS 9.8 Jun 23, 2023

This vulnerability allows remote attackers to execute arbitrary code on Fortinet FortiNAC systems by sending specially crafted requests to the inter-server communication port. Attackers can achieve re...

CVE-2022-39952

CRITICAL CVSS 9.8 Feb 16, 2023

CVE-2022-39952 is a critical path traversal vulnerability in Fortinet FortiNAC that allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests. This aff...

CVE-2022-38375

CRITICAL CVSS 9.1 Feb 16, 2023

CVE-2022-38375 is an improper authorization vulnerability in Fortinet FortiNAC that allows unauthenticated attackers to perform administrative operations via crafted HTTP POST requests. This affects F...

CVE-2023-22633

HIGH CVSS 7.5 Jun 13, 2023

This vulnerability allows unauthenticated attackers to perform denial-of-service (DoS) attacks on FortiNAC devices by exploiting improper access controls in client-secure renegotiation. It affects For...

CVE-2022-40676

HIGH CVSS 7.5 Mar 7, 2023

This is a cross-site scripting (XSS) vulnerability in Fortinet FortiNAC network access control solutions. Attackers can inject malicious scripts via crafted HTTP requests, potentially allowing them to...

CVE-2022-40677

HIGH CVSS 7.2 Feb 16, 2023

This vulnerability allows attackers to execute arbitrary commands on Fortinet FortiNAC systems by injecting malicious arguments through input parameters. It affects multiple versions of FortiNAC netwo...

CVE-2023-22638

HIGH CVSS 7.1 Feb 16, 2023

This vulnerability allows authenticated attackers to perform cross-site scripting (XSS) attacks against FortiNAC network access control systems. Attackers can inject malicious scripts via crafted HTTP...

CVE-2022-26117

HIGH CVSS 8.8 Jul 18, 2022

This vulnerability in FortiNAC allows authenticated attackers to access MySQL databases via the CLI when configuration files contain empty passwords. It affects multiple FortiNAC versions across sever...

CVE-2022-26116

HIGH CVSS 7.2 May 11, 2022

This CVE describes SQL injection vulnerabilities in FortiNAC that allow authenticated attackers to execute unauthorized SQL commands via crafted string parameters. It affects multiple FortiNAC version...

CVE-2021-43065

HIGH CVSS 7.8 Dec 9, 2021

This vulnerability in Fortinet FortiNAC allows attackers to gain elevated privileges by accessing sensitive system data due to incorrect permission assignments. It affects FortiNAC versions 9.2.0, 9.1...

CVE-2021-41021

HIGH CVSS 7.8 Dec 8, 2021

This CVE describes a privilege escalation vulnerability in FortiNAC where an authenticated admin user can elevate privileges to root via sudo command misconfiguration. Affected organizations are those...

CVE-2023-33300

MEDIUM CVSS 5.3 Mar 14, 2025

This command injection vulnerability in Fortinet FortiNAC allows attackers to execute arbitrary commands on affected systems via specially crafted requests to the inter-server communication port. Atta...

CVE-2024-31488

MEDIUM CVSS 6.8 May 14, 2024

This vulnerability allows remote authenticated attackers to inject malicious scripts into FortiNAC web pages, enabling stored and reflected cross-site scripting (XSS) attacks. Attackers can execute ar...