Fortinet FortiNAC是美国飞塔(Fortinet)公司的一种零信任访问解决方案。 Fortinet FortiNAC存在安全漏洞。攻击者利用该漏洞通过特制的HTTP请求执行未经授权的代码或命令。以下版本受到影响:9.4.0版本、9.2.0版本至9.2.5版本、9.1.0版本至9.1.7版本、8.8.0版本至8.8.11版本、8.7.0版本至8.7.6版本、8.6.0版本至8.6.5版本、8.5.0版本至8.5.4版本、8.3.7版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | POC for CVE-2022-39952 | https://github.com/horizon3ai/CVE-2022-39952 | POC Details |
| 2 | Write Behinder_webshell to target using CVE-2022-39952 | https://github.com/shiyeshu/CVE-2022-39952_webshell | POC Details |
| 3 | PoC for CVE-2022-39952 affecting Fortinet FortiNAC. | https://github.com/Chocapikk/CVE-2022-39952 | POC Details |
| 4 | PoC for CVE-2022-39952 affecting Fortinet FortiNAC. | https://github.com/dkstar11q/CVE-2022-39952-better | POC Details |
| 5 | Fortinet FortiNAC is susceptible to arbitrary file write. An external control of the file name or path can allow an attacker to execute unauthorized code or commands via specifically crafted HTTP request, thus making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations. Affected versions are 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, and 8.3.7. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-39952.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-42756 | 9.3 CRITICAL | Fortinet FortiWeb 缓冲区错误漏洞 |
| CVE-2022-41335 | 8.6 HIGH | Fortinet FortiOS和FortiSwitch 路径遍历漏洞 |
| CVE-2022-38375 | 8.6 HIGH | Fortinet FortiNAC 安全漏洞 |
| CVE-2022-41334 | 8.6 HIGH | Fortinet FortiOS 跨站脚本漏洞 |
| CVE-2022-30303 | 8.6 HIGH | Fortinet FortiWeb 操作系统命令注入漏洞 |
| CVE-2021-42761 | 8.5 HIGH | Fortinet FortiWeb 授权问题漏洞 |
| CVE-2022-33869 | 8.0 HIGH | Fortinet FortiWAN 操作系统命令注入漏洞 |
| CVE-2023-23780 | 7.6 HIGH | Fortinet FortiWeb 缓冲区错误漏洞 |
| CVE-2022-40678 | 7.4 HIGH | Fortinet FortiNAC 安全漏洞 |
| CVE-2022-27482 | 7.4 HIGH | Fortinet FortiADC 操作系统命令注入漏洞 |
| CVE-2023-25602 | 7.4 HIGH | Fortinet FortiWeb 缓冲区错误漏洞 |
| CVE-2022-40677 | 7.2 HIGH | Fortinet FortiNAC 参数注入漏洞 |
| CVE-2022-40683 | 7.1 HIGH | Fortinet FortiWeb 资源管理错误漏洞 |
| CVE-2023-23782 | 7.1 HIGH | Fortinet FortiWeb 缓冲区错误漏洞 |
| CVE-2022-27489 | 7.0 HIGH | Fortinet FortiExtender 操作系统命令注入漏洞 |
| CVE-2022-39954 | 6.9 MEDIUM | Fortinet FortiNAC 代码问题漏洞 |
| CVE-2023-22638 | 6.7 MEDIUM | Fortinet FortiNAC 跨站脚本漏洞 |
| CVE-2023-23779 | 6.6 MEDIUM | Fortinet FortiWeb 操作系统命令注入漏洞 |
| CVE-2023-23783 | 6.5 MEDIUM | Fortinet FortiWeb 格式化字符串错误漏洞 |
| CVE-2022-30306 | 6.3 MEDIUM | Fortinet FortiWeb 缓冲区错误漏洞 |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet