Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76xc-486m-c526

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.

EPSS

Процентиль: 4%
0.00138
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-940

Связанные уязвимости

CVSS3: 4.2
nvd
6 месяцев назад

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.

CVSS3: 4.2
fstec
6 месяцев назад

Уязвимость операционных систем Fortinet FortiOS, связанная с недостаточной проверкой источника канала связи, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 4%
0.00138
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-940