7.5

CVE-2023-40718

A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FortinetFortios Ips Engine Version <= 7.312
   FortinetFortios Version >= 7.2.0 < 7.2.4
FortinetFortios Ips Engine Version <= 7.165
   FortinetFortios Version >= 7.0.0 < 7.0.12
FortinetFortios Ips Engine Version <= 6.158
   FortinetFortios Version >= 6.4.0 < 6.4.13
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.084
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
psirt@fortinet.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-436 Interpretation Conflict

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.