CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It affects Fortinet, FortiOS.
CVE
CVE-2023-45586
Severity
MEDIUM
CVSS
5
EPSS
0.29%
Fortinet FortiOS
Original NVD Description
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Related CVEs
Other vulnerabilities affecting the same vendor(s)