From b0e0481761bb4e4456c3146600f8de2fbc210b8d Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Wed, 22 Feb 2023 12:27:53 -0700 Subject: [PATCH] Update fortinet_fortinac_cve_2022_39952.yml fixing --- stories/fortinet_fortinac_cve_2022_39952.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stories/fortinet_fortinac_cve_2022_39952.yml b/stories/fortinet_fortinac_cve_2022_39952.yml index ebeca2ac94..fe43498530 100644 --- a/stories/fortinet_fortinac_cve_2022_39952.yml +++ b/stories/fortinet_fortinac_cve_2022_39952.yml @@ -3,7 +3,7 @@ id: 2833a527-3b7f-41af-a950-39f7bbaff819 version: 1 date: '2023-02-21' author: Michael Haag, Splunk -description: On Thursday, 16 February 2022, Fortinet released a PSIRT that details CVE-2022-39952, a critical vulnerability affecting its FortiNAC product (Horizon3.ai). +description: On Thursday, 16 February 2023, Fortinet released a PSIRT that details CVE-2022-39952, a critical vulnerability affecting its FortiNAC product (Horizon3.ai). narrative: This vulnerability, discovered by Gwendal Guegniaud of Fortinet, allows an unauthenticated attacker to write arbitrary files on the system and as a result obtain remote code execution in the context of the root user (Horizon3.ai). Impacting FortiNAC, is tracked as CVE-2022-39952 and has a CVSS v3 score of 9.8 (critical). FortiNAC is a network access control solution that helps organizations gain real time network visibility, enforce security policies, and detect and mitigate threats.