Privilege escalation via sudo command

Summary

An improper privilege management vulnerability [CWE-269] in FortiNAC may allow a low privilege local user with shell access to execute arbitrary commands as root.

Version Affected Solution
FortiNAC 9.4 9.4.0 through 9.4.1 Upgrade to 9.4.2 or above
FortiNAC 9.2 9.2.0 through 9.2.6 Upgrade to 9.2.7 or above
FortiNAC 9.1 9.1.0 through 9.1.8 Upgrade to 9.1.9 or above
FortiNAC 8.8 8.8 all versions Migrate to a fixed release
FortiNAC 8.7 8.7 all versions Migrate to a fixed release
FortiNAC 8.6 8.6 all versions Migrate to a fixed release
FortiNAC 8.5 8.5 all versions Migrate to a fixed release
FortiNAC 8.3 8.3 all versions Migrate to a fixed release
FortiNAC 7.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2023-03-07: Initial publication