PSIRT Advisories
FortiNAC - argument injection in XML interface on port tcp/5555
Summary
An improper neutralization of special elements used in a command ('command injection') vulnerability [CWE-77] in FortiNAC tcp/5555 service may allow an unauthenticated attacker to copy local files of the device to other local directories of the device via specially crafted input fields. To access the copied data, however, the attacker must have an already existing foothold on the device with sufficient privileges
Major Version | Affected Products | Solutions |
---|---|---|
9.4 | FortiNAC version 9.4.0 through 9.4.3 | Please upgrade to FortiNAC version 9.4.4 or above |
7.2 | FortiNAC version 7.2.0 through 7.2.1 | Please upgrade to FortiNAC version 7.2.2 or above |