FortiNAC - argument injection in XML interface on port tcp/5555

Summary

An improper neutralization of special elements used in a command ('command injection') vulnerability [CWE-77] in FortiNAC tcp/5555 service may allow an unauthenticated attacker to copy local files of the device to other local directories of the device via specially crafted input fields. To access the copied data, however, the attacker must have an already existing foothold on the device with sufficient privileges

Version Affected Solution
FortiNAC 9.4 9.4.0 through 9.4.3 Upgrade to 9.4.4 or above
FortiNAC 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above

Acknowledgement

Fortinet is pleased to thank Florian Hauser from CODE WHITE for reporting this vulnerability under responsible disclosure.

Timeline

2023-06-19: Initial publication