Unauthenticated access to administrative operations

Summary

An improper authorization vulnerability [CWE-285] in FortiNAC may allow an unauthenticated attacker to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

Affected Products

FortiNAC version 9.4.0 through 9.4.1
FortiNAC version 9.2.0 through 9.2.6
FortiNAC 9.1 all versions are not affected
FortiNAC 8.8 all versions are not affected
FortiNAC 8.7 all versions are not affected
FortiNAC 8.6 all versions are not affected
FortiNAC 8.5 all versions are not affected
FortiNAC 7.2 all versions are not affected

Solutions

Please upgrade to FortiNAC-F version 7.2.0 or above
Please upgrade to FortiNAC version 9.4.2 or above
Please upgrade to FortiNAC version 9.2.7 or above

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2023-02-16: Initial publication