ID

VAR-202306-1039


CVE

CVE-2023-22633


TITLE

Fortinet FortiNAC Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202306-889

DESCRIPTION

An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attack on the device via client-secure renegotiation. Fortinet FortiNAC is a network access control solution developed by Fortinet. This product is mainly used for network access control and IoT security protection. Fortinet FortiNAC has a security flaw that stems from improper permissions, privileges, and access control flaws

Trust: 1.44

sources: NVD: CVE-2023-22633 // CNNVD: CNNVD-202306-889

AFFECTED PRODUCTS

vendor:fortinetmodel:fortinacscope:gteversion:8.7.0

Trust: 1.0

vendor:fortinetmodel:fortinacscope:eqversion:9.4.1

Trust: 1.0

vendor:fortinetmodel:fortinacscope:lteversion:9.1.8

Trust: 1.0

vendor:fortinetmodel:fortinacscope:gteversion:9.2.0

Trust: 1.0

vendor:fortinetmodel:fortinacscope:gteversion:8.8.0

Trust: 1.0

vendor:fortinetmodel:fortinacscope:lteversion:8.7.6

Trust: 1.0

vendor:fortinetmodel:fortinacscope:lteversion:9.2.6

Trust: 1.0

vendor:fortinetmodel:fortinacscope:lteversion:8.8.11

Trust: 1.0

vendor:fortinetmodel:fortinacscope:eqversion:9.4.0

Trust: 1.0

vendor:fortinetmodel:fortinacscope:gteversion:9.1.0

Trust: 1.0

vendor:fortinetmodel:fortinac-fscope:eqversion:7.2.0

Trust: 1.0

sources: NVD: CVE-2023-22633

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2023-22633
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202306-889
value: HIGH

Trust: 0.6

NVD: CVE-2023-22633
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: NVD: CVE-2023-22633 // CNNVD: CNNVD-202306-889

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2023-22633

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202306-889

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202306-889

CONFIGURATIONS

sources: NVD: CVE-2023-22633

EXTERNAL IDS

db:NVDid:CVE-2023-22633

Trust: 1.6

db:CNNVDid:CNNVD-202306-889

Trust: 0.6

sources: NVD: CVE-2023-22633 // CNNVD: CNNVD-202306-889

REFERENCES

url:https://fortiguard.com/psirt/fg-ir-22-521

Trust: 1.6

url:https://cxsecurity.com/cveshow/cve-2023-22633/

Trust: 0.6

sources: NVD: CVE-2023-22633 // CNNVD: CNNVD-202306-889

SOURCES

db:NVDid:CVE-2023-22633
db:CNNVDid:CNNVD-202306-889

LAST UPDATE DATE

2023-06-19T22:49:05.461000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2023-22633date:2023-06-17T01:40:00
db:CNNVDid:CNNVD-202306-889date:2023-06-19T00:00:00

SOURCES RELEASE DATE

db:NVDid:CVE-2023-22633date:2023-06-13T09:15:00
db:CNNVDid:CNNVD-202306-889date:2023-06-13T00:00:00