Command Injection in FortiNAC-F and FortiNAC - CVE-2023-33300
Published: June 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to manipulate files on the device.
The vulnerability exist due to improper input validation when processing requests sent to the XML interface on port 5555/TCP. A remote non-authenticated attacker can send a specially crafted request to the system and copy local files of the device to other local directories of the device.
Affected software
FortiNAC
How to mitigate CVE-2023-33300
FortiNAC - update to 9.4.3