Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wjq-4wff-qw9c

Опубликовано: 16 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

EPSS

Процентиль: 100%
0.93777
Критический

9.8 Critical

CVSS3

Дефекты

CWE-610

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

CVSS3: 9.8
fstec
почти 3 года назад

Уязвимость компонента keyUpload средства управления доступом к сети Fortinet FortiNAC, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.93777
Критический

9.8 Critical

CVSS3

Дефекты

CWE-610