CVE-2022-39952 is a critical vulnerability affecting multiple versions of Fortinet FortiNAC, allowing unauthenticated attackers to execute arbitrary code or commands through specially crafted HTTP requests. With a CVSS score of 9.8 (Critical), this flaw can be exploited remotely with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While not yet listed in KEV, exploit code is publicly available via Metasploit and Nuclei templates, and it has garnered significant community discussion and media coverage, indicating a high likelihood of active exploitation. Organizations are strongly urged to patch immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5.0, <= 8.5.4CPE match | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* | ||
>= 8.6.0, <= 8.6.5CPE match | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* | ||
>= 8.7.0, <= 8.7.6CPE match | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* | ||
>= 8.8.0, <= 8.8.11CPE match | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* | ||
>= 9.1.0, <= 9.1.7CPE match | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.