From b65986eb718ac8a71d3229cfd2670ce8a4c886ba Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Tue, 21 Feb 2023 11:07:04 -0700 Subject: [PATCH] Update fortinet_fortinac_cve_2022_39952.yml --- stories/fortinet_fortinac_cve_2022_39952.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stories/fortinet_fortinac_cve_2022_39952.yml b/stories/fortinet_fortinac_cve_2022_39952.yml index d13d466766..ad19714e39 100644 --- a/stories/fortinet_fortinac_cve_2022_39952.yml +++ b/stories/fortinet_fortinac_cve_2022_39952.yml @@ -7,7 +7,7 @@ description: On Thursday, 16 February 2022, Fortinet released a PSIRT that detai narrative: This vulnerability, discovered by Gwendal Guégniaud of Fortinet, allows an unauthenticated attacker to write arbitrary files on the system and as a result obtain remote code execution in the context of the root user (Horizon3.ai). Impacting FortiNAC, is tracked as CVE-2022-39952 and has a CVSS v3 score of 9.8 (critical). FortiNAC is a network access control solution that helps organizations gain real-time network visibility, enforce security policies, and detect and mitigate threats. - "An external control of file name or path vulnerability [CWE-73] in FortiNAC webserver may allow an unauthenticated attacker to perform arbitrary write on the system," reads the security advisory. + An external control of file name or path vulnerability [CWE-73] in FortiNAC webserver may allow an unauthenticated attacker to perform arbitrary write on the system, reads the security advisory. references: - https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/ - https://viz.greynoise.io/tag/fortinac-rce-attempt?days=30