Loading
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
Use CWE-73, Fortinet vendor hub and Fortinac product page to widen CVE-2022-39952 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-33299, CVE-2022-39946 and CVE-2023-22633 for nearby disclosures in the same product family.