CVE-2023-48785: Medium severity fortinet fortinac vulnerability
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48785?
CVE-2023-48785 is classified as a critical severity vulnerability due to its potential to allow remote attackers to intercept sensitive communications.
How do I fix CVE-2023-48785?
To fix CVE-2023-48785, upgrade FortiNAC-F to version 7.2.5 or higher where the vulnerability is addressed.
Who is affected by CVE-2023-48785?
CVE-2023-48785 affects all installations of FortiNAC-F version 7.2.4 and below.
What type of attack does CVE-2023-48785 enable?
CVE-2023-48785 enables attackers to perform a Man-in-the-Middle attack on HTTPS communications.
Is CVE-2023-48785 a remote vulnerability?
Yes, CVE-2023-48785 can be exploited by remote and unauthenticated attackers.