CVE-2024-23105

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection throug

Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.004
36.5th percentile
Discovered by
Not disclosed
Published
May 14, 2024
Assigned by fortinet

Description

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.

Weakness: CWE-348

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported affected versions (3)
  • Fortinet · FortiPortal
  • fortinet · fortiportal
  • fortinet · fortiportal

Vendor remediation

Please upgrade to FortiPortal version 7.2.2 or above Please upgrade to FortiPortal version 7.0.7 or above