← back
CVE-2023-26203

CVE-2023-26203

CVSS 6.1 MEDIUMEPSS 0.2%CWE-798
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shell commands.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Affected products
Fortinet · FortiNAC

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →