A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
2025-06-10T17:19:25.660
2025-07-25T15:25:35.410
Analyzed
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | < 7.0.17 | Yes |
Application | fortinet | fortiproxy | < 7.2.10 | Yes |
Application | fortinet | fortiproxy | < 7.4.4 | Yes |
Operating System | fortinet | fortios | < 7.2.9 | Yes |
Operating System | fortinet | fortios | < 7.4.4 | Yes |