CVE-2023-46715: IPsec dynamic assignation IP spoofing
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Other sources
An origin validation error [CWE-346] vulnerability in FortiOS IPSec VPN may allow an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46715?
CVE-2023-46715 is considered a significant vulnerability due to its potential to allow spoofing attacks by authenticated IPSec VPN users.
How do I fix CVE-2023-46715?
To remediate CVE-2023-46715, upgrade FortiOS to version 7.4.2 or later.
Which versions of FortiOS are affected by CVE-2023-46715?
CVE-2023-46715 affects FortiOS versions 7.4.0 to 7.4.1 and 7.2.6 and below.
Can unauthenticated users exploit CVE-2023-46715?
No, CVE-2023-46715 requires authenticated IPSec VPN users to exploit the vulnerability.
What is the nature of the vulnerability in CVE-2023-46715?
CVE-2023-46715 is an origin validation error that allows packet spoofing between authenticated users.