High severity7.2NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026
CVE-2022-40677
CVE-2022-40677
Description
A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters.
Affected products
59.4.0, 9.2.0-9.2.5, 9.1.0-9.1.7, 8.8.0-8.8.11, 8.7.0-8.7.6, 8.6.0-8.6.5, 8.5.0-8.5.4, 8.3.7+ 1 more
- (no CPE)range: 9.4.0, 9.2.0-9.2.5, 9.1.0-9.1.7, 8.8.0-8.8.11, 8.7.0-8.7.6, 8.6.0-8.6.5, 8.5.0-8.5.4, 8.3.7
- (no CPE)range: 9.4.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-280nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.