Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6xx-gv82-hc4m

Опубликовано: 10 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.

EPSS

Процентиль: 2%
0.00013
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-300

Связанные уязвимости

CVSS3: 5.9
nvd
8 месяцев назад

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.

CVSS3: 5.9
fstec
8 месяцев назад

Уязвимость графического интерфейса операционных систем Fortinet FortiOS и прокси-сервера для защиты от интернет-атак FortiProxy, позволяющая нарушителю выполнить атаку типа «человек посередине»

EPSS

Процентиль: 2%
0.00013
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-300