First published: Tue Jan 14 2025(Updated: )
An origin validation error [CWE-346] vulnerability in FortiOS IPSec VPN may allow an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | >=7.4.0<=7.4.1 | |
Fortinet FortiOS IPS Engine | >=7.2 | |
Fortinet FortiOS IPS Engine | >=7.0 | |
Fortinet FortiOS IPS Engine | >=6.4 | |
Fortinet FortiOS IPS Engine | >=6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
FG-IR-23-407 is classified as a moderate severity vulnerability.
To fix FG-IR-23-407, upgrade FortiOS to version 7.4.2 or later.
FG-IR-23-407 affects FortiOS versions 7.4.0 to 7.4.1, as well as versions 7.0, 6.4, 6.2, and 7.2.
FG-IR-23-407 is an origin validation error categorized under CWE-346.
The vendor for FG-IR-23-407 is Fortinet.