CVE-2023-45586: Fortinet FortiOS
Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
Affected products
- Fortinet FortiOS: from 6.2.0, up to and including 6.2.16; from 6.4.0, up to and including 6.4.15; from 7.0.0, before 7.0.13 (fixed in 7.0.13); from 7.2.0, before 7.2.8 (fixed in 7.2.8); version 7.4.0 only; version 7.4.1 only
- Fortinet FortiProxy: from 2.0.0, up to and including 2.0.12; from 7.0.0, before 7.0.14 (fixed in 7.0.14); from 7.2.0, before 7.2.8 (fixed in 7.2.8); version 7.4.0 only; version 7.4.1 only
Published 2024-05-14. Last modified 2026-06-17.