Vulnerability Details CVE-2022-39954
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.6%
CVSS Severity
CVSS v3 Score 7.3
Products affected by CVE-2022-39954
-
cpe:2.3:a:fortinet:fortinac-f:-
-
cpe:2.3:a:fortinet:fortinac:8.3.7
-
cpe:2.3:a:fortinet:fortinac:8.5.0
-
cpe:2.3:a:fortinet:fortinac:8.5.1
-
cpe:2.3:a:fortinet:fortinac:8.5.2
-
cpe:2.3:a:fortinet:fortinac:8.5.3
-
cpe:2.3:a:fortinet:fortinac:8.5.4
-
cpe:2.3:a:fortinet:fortinac:8.6.0
-
cpe:2.3:a:fortinet:fortinac:8.6.1
-
cpe:2.3:a:fortinet:fortinac:8.6.2
-
cpe:2.3:a:fortinet:fortinac:8.6.3
-
cpe:2.3:a:fortinet:fortinac:8.6.4
-
cpe:2.3:a:fortinet:fortinac:8.6.5
-
cpe:2.3:a:fortinet:fortinac:8.7.0
-
cpe:2.3:a:fortinet:fortinac:8.7.1
-
cpe:2.3:a:fortinet:fortinac:8.7.2
-
cpe:2.3:a:fortinet:fortinac:8.7.3
-
cpe:2.3:a:fortinet:fortinac:8.7.4
-
cpe:2.3:a:fortinet:fortinac:8.7.5
-
cpe:2.3:a:fortinet:fortinac:8.7.6
-
cpe:2.3:a:fortinet:fortinac:8.8.0
-
cpe:2.3:a:fortinet:fortinac:8.8.1
-
cpe:2.3:a:fortinet:fortinac:8.8.10
-
cpe:2.3:a:fortinet:fortinac:8.8.11
-
cpe:2.3:a:fortinet:fortinac:8.8.2
-
cpe:2.3:a:fortinet:fortinac:8.8.3
-
cpe:2.3:a:fortinet:fortinac:8.8.4
-
cpe:2.3:a:fortinet:fortinac:8.8.5
-
cpe:2.3:a:fortinet:fortinac:8.8.6
-
cpe:2.3:a:fortinet:fortinac:8.8.7
-
cpe:2.3:a:fortinet:fortinac:8.8.8
-
cpe:2.3:a:fortinet:fortinac:8.8.9
-
cpe:2.3:a:fortinet:fortinac:9.1.0
-
cpe:2.3:a:fortinet:fortinac:9.1.1
-
cpe:2.3:a:fortinet:fortinac:9.1.10
-
cpe:2.3:a:fortinet:fortinac:9.1.2
-
cpe:2.3:a:fortinet:fortinac:9.1.3
-
cpe:2.3:a:fortinet:fortinac:9.1.4
-
cpe:2.3:a:fortinet:fortinac:9.1.5
-
cpe:2.3:a:fortinet:fortinac:9.1.6
-
cpe:2.3:a:fortinet:fortinac:9.1.7
-
cpe:2.3:a:fortinet:fortinac:9.1.8
-
cpe:2.3:a:fortinet:fortinac:9.1.9
-
cpe:2.3:a:fortinet:fortinac:9.2.0
-
cpe:2.3:a:fortinet:fortinac:9.2.1
-
cpe:2.3:a:fortinet:fortinac:9.2.2
-
cpe:2.3:a:fortinet:fortinac:9.2.3
-
cpe:2.3:a:fortinet:fortinac:9.2.4
-
cpe:2.3:a:fortinet:fortinac:9.2.5
-
cpe:2.3:a:fortinet:fortinac:9.2.6
-
cpe:2.3:a:fortinet:fortinac:9.2.7
-
cpe:2.3:a:fortinet:fortinac:9.4.0
-
cpe:2.3:a:fortinet:fortinac:9.4.1