Vulnerability Details CVE-2023-48785
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.1%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2023-48785
-
cpe:2.3:a:fortinet:fortinac-f:7.2.0
-
cpe:2.3:a:fortinet:fortinac-f:7.2.1
-
cpe:2.3:a:fortinet:fortinac-f:7.2.2
-
cpe:2.3:a:fortinet:fortinac-f:7.2.3
-
cpe:2.3:a:fortinet:fortinac-f:7.2.4