CVE-2023-45586: SSL-VPN user IP spoofing
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Other sources
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiOS & FortiProxy SSL-VPN tunnel mode may allow an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45586?
CVE-2023-45586 has been classified with a high severity due to insufficient verification of data authenticity.
How do I fix CVE-2023-45586?
To fix CVE-2023-45586, upgrade FortiOS SSL-VPN versions to 7.4.2, 7.2.8, or 7.0.13 or later.
Which versions are affected by CVE-2023-45586?
CVE-2023-45586 affects Fortinet FortiOS versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.7, and pre-7.0.12.
Does CVE-2023-45586 affect FortiProxy?
Yes, CVE-2023-45586 also affects FortiProxy versions 7.4.0 to 7.4.1 and 7.2.0 to 7.2.7.
What is the CVSS score of CVE-2023-45586?
CVE-2023-45586 has a CVSS score that indicates a high risk to the confidentiality, integrity, and availability of affected systems.