VDB
CVE-2024-23112
CVE-2024-23112
PUBLISHED
Es besteht eine Schwachstelle in Fortinet FortiOS und Fortinet FortiProxy. Dieser Fehler besteht in der SSLVPN-Komponente aufgrund einer unsachgemäßen Zugriffskontrolle, die es ermöglicht, über URL-Manipulationen Zugriff auf das Lesezeichen eines anderen Benutzers zu erhalten. Ein authentifizierter Angreifer im lokalen Netz kann diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen.
EPSS 0.06% · 17.9th percentile
Risk Scores
EPSS Score
0.06%
17.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortinet FortiOS <7.4.2 | |
| Fortinet | Fortinet FortiOS <6.4.15 | |
| Fortinet | Fortinet FortiOS <7.2.6 | |
| Fortinet | Fortinet FortiProxy <7.0.15 | |
| Fortinet | Fortinet FortiProxy <7.0.13 | |
| Fortinet | Fortinet FortiProxy <7.2.9 | |
| Fortinet | Fortinet FortiOS <7.2.7 | |
| Fortinet | Fortinet FortiOS <7.0.14 | |
| Fortinet | Fortinet FortiProxy <7.4.3 | |
| Fortinet | Fortinet FortiProxy <2.0.14 | |
| Fortinet | Fortinet FortiProxy <7.4.1 | |
| Fortinet | Fortinet FortiOS <6.2.16 | |
| Fortinet | Fortinet FortiOS <7.0.13 | |
| Fortinet | Fortinet FortiProxy <7.2.7 |
Exploit Intelligence
- CIRCL seen: CVE-2024-23112 (circl-sighting)
- CIRCL seen: CVE-2024-23112 (circl-sighting)
- CIRCL seen: CVE-2024-23112 (circl-sighting)
- https://fortiguard.com/psirt/FG-IR-24-013 (circl)
- https://github.com/CrimBit/CVE-2023-42789-POC (certbund)
Timeline
- Mar 12, 2024 CVE Published
- Mar 12, 2024 PoC Published
- Mar 12, 2024 PoC Published
- Mar 13, 2024 EPSS Score
- Mar 13, 2024 PoC Published
- Apr 8, 2024 EPSS Score
- May 4, 2024 EPSS Score
- Jun 25, 2024 EPSS Score
- Jul 22, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Aug 17, 2024 EPSS Score
- Sep 12, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0617.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0617 advisory
- https://github.com/CrimBit/CVE-2023-42789-POC exploit
- https://fortiguard.fortinet.com/psirt/FG-IR-23-328 advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-24-013 advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-23-424 advisory