An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version 8.6.0 through 8.6.5, FortiNAC version 8.5.0 through 8.5.4, FortiNAC version 8.3.7 allows attacker to read arbitrary files or trigger a denial of service via specifically crafted XML documents.
Use CWE-611, Fortinet vendor hub and Fortinac product page to widen CVE-2022-39954 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-33299, CVE-2022-39946 and CVE-2023-22633 for nearby disclosures in the same product family.