CVE-2022-38375: Fortinet Fortinac
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
Affected products
- Fortinet Fortinac: from 9.2.0, before 9.2.7 (fixed in 9.2.7); from 9.4.0, before 9.4.2 (fixed in 9.4.2)
- Fortinet Fortinac-F: before 7.2.0 (fixed in 7.2.0)
Published 2023-02-16. Last modified 2026-06-17.