Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiNAC version 9.4.4 or above Please upgrade to FortiNAC version 7.2.2 or above
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37463 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port. |
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-096 |
|
Wed, 23 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Mar 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port. | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-03-14T17:24:11.918Z
Reserved: 2023-05-22T07:58:22.196Z
Link: CVE-2023-33300
Updated: 2025-03-14T17:24:07.524Z
Status : Analyzed
Published: 2025-03-14T16:15:27.203
Modified: 2025-07-23T21:13:27.477
Link: CVE-2023-33300
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:32:05Z
EUVD