QID 730834

Date Published: 2023-06-27

QID 730834: FortiNAC Unauthenticated Remote Code Execution (RCE) Vulnerability (FG-IR-23-074)

FortiNAC is a zero-trust access solution that oversees and protects all digital assets connected to the enterprise network, covering devices ranging from IT, IoT, OT/ICS, to IoMT.

A deserialization of untrusted data vulnerability in FortiNAC may allow an unauthenticated user to execute unauthorized code or commands via specifically crafted requests to the tcp/1050 service.

Affected versions:
FortiNAC version 9.4.0 through 9.4.2
FortiNAC version 9.2.0 through 9.2.7
FortiNAC version 9.1.0 through 9.1.9
FortiNAC version 7.2.0 through 7.2.1
FortiNAC 8.8 all versions
FortiNAC 8.7 all versions
FortiNAC 8.6 all versions
FortiNAC 8.5 all versions
FortiNAC 8.3 all versions

QID Detection Logic:
This unauthenticated detection will sends a GET request to "/actions/system/local-properties/software-details" endpoint and checks for the affected installed version.

Successful exploitation of this vulnerability may allow an unauthenticated user to execute unauthorized code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to latest FortiNAC versions. Please refer to FG-IR-23-074 vendor advisory for further information.
    Vendor References

    CVEs related to QID 730834

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-074 URL Logo www.fortiguard.com/psirt/FG-IR-23-074