CVE-2024-23105
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection throug
Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.004
36.5th percentile
Discovered by
Not disclosed
Published
May 14, 2024
Assigned by fortinet
Description
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
Weakness: CWE-348
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPortal | Network & Security Management | cna-assigner |
Vendor-reported affected versions (3)
- Fortinet · FortiPortal
- fortinet · fortiportal
- fortinet · fortiportal
Vendor remediation
Please upgrade to FortiPortal version 7.2.2 or above Please upgrade to FortiPortal version 7.0.7 or above