← Retour aux CVEs
CVE-2023-33299
CRITICAL9.8
Description
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie6/23/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
fortinet:fortinac
Faiblesses (CWE)
CWE-502CWE-502
References
https://fortiguard.com/psirt/FG-IR-23-074(psirt@fortinet.com)
https://fortiguard.com/psirt/FG-IR-23-074(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.