QID 730834
Date Published: 2023-06-27
QID 730834: FortiNAC Unauthenticated Remote Code Execution (RCE) Vulnerability (FG-IR-23-074)
FortiNAC is a zero-trust access solution that oversees and protects all digital assets connected to the enterprise network, covering devices ranging from IT, IoT, OT/ICS, to IoMT.
A deserialization of untrusted data vulnerability in FortiNAC may allow an unauthenticated user to execute unauthorized code or commands via specifically crafted requests to the tcp/1050 service.
Affected versions:
FortiNAC version 9.4.0 through 9.4.2
FortiNAC version 9.2.0 through 9.2.7
FortiNAC version 9.1.0 through 9.1.9
FortiNAC version 7.2.0 through 7.2.1
FortiNAC 8.8 all versions
FortiNAC 8.7 all versions
FortiNAC 8.6 all versions
FortiNAC 8.5 all versions
FortiNAC 8.3 all versions
QID Detection Logic:
This unauthenticated detection will sends a GET request to "/actions/system/local-properties/software-details" endpoint and checks for the affected installed version.
Successful exploitation of this vulnerability may allow an unauthenticated user to execute unauthorized code on the target system.
- FG-IR-23-074 -
www.fortiguard.com/psirt/FG-IR-23-074
CVEs related to QID 730834
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-074 |
|