VYPR
Medium severity5.3NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026

CVE-2022-43951

CVE-2022-43951

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests.

Affected products

4
  • cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*:*range: <7.2.0
    • (no CPE)range: <=9.4.1, <=9.2.6, <=9.1.8, <=8.8.11, <=8.7.6
    • (no CPE)range: 9.4.0
  • cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
    Range: >=8.7.0,<=9.2.7

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.