CVE-2022-39952
CRITICAL 9.8EPSS 99.8%
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.81% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical
- Published
- 2023-02-16
- Updated
- 2024-10-23
Proof-of-concept exploits (4)
- Chocapikk/CVE-2022-399523★ · 2023-02-26
- dkstar11q/CVE-2022-39952-better0★ · 2023-02-26
- horizon3ai/CVE-2022-39952265★ · 2023-02-25
- shiyeshu/CVE-2022-39952_webshell2★ · 2023-02-22