CVE-2024-23105
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection throug
Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.004
38.1th percentile
Discovered by
Vendor
Vendor advisory field
Published
May 14, 2024
Assigned by fortinet
Description
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
Weakness: CWE-348
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPortal | Network & Security Management | cna-assigner |
Vendor-reported products (3)
- Fortinet · FortiPortal
- fortinet · fortiportal
- fortinet · fortiportal
Credit
Internally discovered and reported by Théo Leleu of Fortinet Product Security team.
Vendor remediation
Please upgrade to FortiPortal version 7.2.2 or above Please upgrade to FortiPortal version 7.0.7 or above