CVE Vulnerabilities

CVE-2023-28002

Improper Validation of Integrity Check Value

Published: Nov 14, 2023 | Modified: Nov 20, 2023
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.2 all versions, 7.0 all versions, 2.0 all versions VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

Name Vendor Start Version End Version
Fortiproxy Fortinet 2.0.0 (including) 2.0.13 (including)
Fortiproxy Fortinet 7.0.0 (including) 7.0.13 (including)
Fortiproxy Fortinet 7.2.0 (including) 7.2.7 (including)
Fortios Fortinet 6.0.0 (including) 6.0.17 (including)
Fortios Fortinet 6.2.0 (including) 6.2.15 (including)
Fortios Fortinet 6.4.0 (including) 6.4.14 (including)
Fortios Fortinet 7.0.0 (including) 7.0.12 (including)
Fortios Fortinet 7.2.0 (including) 7.2.3 (including)

Potential Mitigations

References