CVE Vulnerabilities

CVE-2024-23105

Use of Less Trusted Source

Published: May 14, 2024 | Modified: May 23, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.

Weakness

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Affected Software

Name Vendor Start Version End Version
Fortiportal Fortinet 7.0.0 (including) 7.0.6 (including)
Fortiportal Fortinet 7.2.0 (including) 7.2.0 (including)
Fortiportal Fortinet 7.2.1 (including) 7.2.1 (including)

References