Aller au contenu

Fiche vulnérabilité

CVE-2023-48785 : faille moyenne fortinet fortinac-f (CVSS 4.8)

Description

An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.

En bref

Sévérité
Moyenne (CVSS 4.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
14 mars 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • fortinet fortinac-f

Références

Rechercher une autre vulnérabilité dans la base CVE