Lucene search

K
fortinetFortiGuard LabsFG-IR-22-304
HistoryFeb 16, 2023 - 12:00 a.m.

FortiNAC - Multiple XML external entity (XXE) injection

2023-02-1600:00:00
FortiGuard Labs
www.fortiguard.com
14
fortinac
xml
xxe
injection
cwe-611
denial of service
file system

EPSS

0.002

Percentile

58.0%

An improper restriction of XML external entity reference vulnerability [CWE-611] in the parser of XML requests of FortiNAC may allow an unauthenticated attacker to trigger a denial of service or read arbitrary files from the underlying file system via specifically crafted XML documents.

EPSS

0.002

Percentile

58.0%

Related for FG-IR-22-304