Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952: networkNetworkNoneversion:11
The following analytic detects attempts to exploit the Fortinet FortiNAC CVE-2022-39952 vulnerability. It identifies HTTP POST requests to the URI configWizard/keyUpload.jsp with a payload.zip file.
The detection leverages the Web datamodel, analyzing fields such as URL, HTTP method, and user agent.
This activity is significant as it indicates an attempt to exploit a known vulnerability, potentially leading to remote code execution.
If confirmed malicious, attackers could gain control over the affected system, schedule malicious tasks, and establish persistent access via a remote command and control (C2) server.