CVE-2023-28002 is an integrity check bypass vulnerability (CWE-354) affecting multiple versions of Fortinet FortiOS and FortiProxy. A local attacker with administrative privileges can exploit this flaw to boot a malicious image, circumventing the device's filesystem integrity checks. Rated 6.7 MEDIUM, the vulnerability requires high privileges and local access, but successful exploitation could lead to high confidentiality, integrity, and availability impacts. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.0.13CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.13CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.7CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.0.17CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.2.0, <= 6.2.15CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.