Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-48785


An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.


Published

2025-03-14T16:15:27.733

Last Modified

2025-07-25T15:08:45.760

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortinac-f < 7.2.5 Yes

References