First published: Tue May 14 2024(Updated: )
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | >=7.4.0<=7.4.1 | |
Fortinet FortiOS IPS Engine | >=7.2.0<=7.2.7 | |
Fortinet FortiOS IPS Engine | >=7.0.0<=7.0.12 | |
Fortinet FortiOS IPS Engine | >=6.4 | |
Fortinet FortiOS IPS Engine | >=6.2 | |
Fortinet FortiProxy | >=7.4.0<=7.4.1 | |
Fortinet FortiProxy | >=7.2.0<=7.2.7 | |
Fortinet FortiProxy | >=7.0.0<=7.0.13 | |
Fortinet FortiProxy | >=2.0 | |
Fortinet FortiProxy | >=2.0.0<=2.0.12 | |
Fortinet FortiProxy | >=7.0.0<7.0.14 | |
Fortinet FortiProxy | >=7.2.0<7.2.8 | |
Fortinet FortiProxy | =7.4.0 | |
Fortinet FortiProxy | =7.4.1 | |
Fortinet FortiOS IPS Engine | >=6.2.0<=6.2.16 | |
Fortinet FortiOS IPS Engine | >=6.4.0<=6.4.15 | |
Fortinet FortiOS IPS Engine | >=7.0.0<7.0.13 | |
Fortinet FortiOS IPS Engine | >=7.2.0<7.2.8 | |
Fortinet FortiOS IPS Engine | =7.4.0 | |
Fortinet FortiOS IPS Engine | =7.4.1 |
Please upgrade to FortiProxy version 7.4.2 or above Please upgrade to FortiProxy version 7.2.8 or above Please upgrade to FortiProxy version 7.0.14 or above Please upgrade to FortiOS version 7.4.2 or above Please upgrade to FortiOS version 7.2.8 or above Please upgrade to FortiOS version 7.0.13 or above Please upgrade to FortiSASE version 23.4.a or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45586 has been classified with a high severity due to insufficient verification of data authenticity.
To fix CVE-2023-45586, upgrade FortiOS SSL-VPN versions to 7.4.2, 7.2.8, or 7.0.13 or later.
CVE-2023-45586 affects Fortinet FortiOS versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.7, and pre-7.0.12.
Yes, CVE-2023-45586 also affects FortiProxy versions 7.4.0 to 7.4.1 and 7.2.0 to 7.2.7.
CVE-2023-45586 has a CVSS score that indicates a high risk to the confidentiality, integrity, and availability of affected systems.