CVE-2022-26116
Summary
| CVE | CVE-2022-26116 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-11 08:15:00 UTC |
| Updated | 2022-05-18 19:37:00 UTC |
| Description | Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Fortinac | 8.5.4 | All | All | All |
| Application | Fortinet | Fortinac | 8.6.0 | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
| Application | Fortinet | Fortinac | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PSIRT Advisories | FortiGuard | CONFIRM | fortiguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.