CVE-2023-45586 Details
Description
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fortiguard.com/psirt/FG-IR-23-225 | CVE | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-23-225 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet fortiproxy | >= 2.0.0, <= 2.0.12 >= 7.0.0, < 7.0.14 >= 7.2.0, < 7.2.8 7.4.0 7.4.1 |
CPE
Remediation
| |
| fortinet fortios | >= 6.2.0, <= 6.2.16 >= 6.4.0, <= 6.4.15 >= 7.0.0, < 7.0.13 >= 7.2.0, < 7.2.8 7.4.0 7.4.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 4, 2024 | CVE Modified | [email protected] |
| May 23, 2024 | Initial Analysis | [email protected] |
| May 14, 2024 | New CVE Received | [email protected] |