CVE-2023-48785
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2023-48785 is a vulnerability affecting FortiNAC-F versions 7.2.4 and below. This issue involves improper certificate validation (CWE-295), which can enable a remote, unauthenticated attacker to carry out Man-in-the-Middle attacks. As a result, the attacker could potentially intercept and modify HTTPS communication channels between a FortiOS device, an inventory, and FortiNAC-F. This weakness poses a significant risk to data integrity and confidentiality. Organizations utilizing these FortiNAC-F versions are advised to apply the necessary patches as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Fortinet