Back

MEDIUM

A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal

Published Apr 11, 2023

Description

A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.

Affected products

Remediation

Vendor solution

Please upgrade to FortiOS version 7.2.4 or above Please upgrade to FortiOS version 7.0.11 or above

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner fortinet
Published Apr 11, 2023
Updated Oct 22, 2024
Reserved Oct 7, 2022

CISA Vulnrichment

Updated Oct 22, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner fortinet
Published Apr 11, 2023
Updated Oct 22, 2024

GitHub

No data