CVE-2024-23105

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection throug

Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.004
38.1th percentile
Discovered by
Vendor
Vendor advisory field
Published
May 14, 2024
Assigned by fortinet

Description

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.

Weakness: CWE-348

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiPortal
  • fortinet · fortiportal
  • fortinet · fortiportal

Credit

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Vendor remediation

Please upgrade to FortiPortal version 7.2.2 or above Please upgrade to FortiPortal version 7.0.7 or above

Something wrong here?