CVE-2023-46715

An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-23-407 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

31 Jan 2025, 17:20

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-23-407 - () https://fortiguard.com/psirt/FG-IR-23-407 - Vendor Advisory
CPE cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortios
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

14 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 14:15

Updated : 2025-01-31 17:20


NVD link : CVE-2023-46715

Mitre link : CVE-2023-46715


JSON object : View

Products Affected

fortinet

  • fortios
CWE
CWE-346

Origin Validation Error