CVE-2023-40718

Description

A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets.

Remediation

Solution:

  • IPS Engine manual download is not needed unless device is offline and cannot download IPS Engine update automatically. Fixed in IPS Engine version 6.0159 and later.   FortiOS 6.4.13 and later contains IPS engine 6.0160 as the default IPS Engine.   IPS Engine 6.0162 is downloadable from FortiGuard by FortiGate units with a valid subscription running FortiOS 6.4.x. Fixed in IPS Engine version 7.0166 and later.   FortiOS 7.0.12 and later contains IPS engine 7.0167 as the default IPS Engine. Fixed in IPS Engine version 7.0313 and later.   FortiOS 7.2.5 and later contains IPS engine 7.0314 as the default IPS Engine.   IPS Engine 7.0322 is downloadable from FortiGuard by FortiGate units with a valid subscription running FortiOS 7.2.x. FortiOS 7.4.0 and later contains IPS engine 7.0493 as the default IPS Engine.  

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.04%
Vendor Advisory fortiguard.com
Affected: Fortinet IPS Engine
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-40718?
CVE-2023-40718 has been scored as a high severity vulnerability.
How to fix CVE-2023-40718?
To fix CVE-2023-40718: IPS Engine manual download is not needed unless device is offline and cannot download IPS Engine update automatically. Fixed in IPS Engine version 6.0159 and later.   FortiOS 6.4.13 and later contains IPS engine 6.0160 as the default IPS Engine.   IPS Engine 6.0162 is downloadable from FortiGuard by FortiGate units with a valid subscription running FortiOS 6.4.x. Fixed in IPS Engine version 7.0166 and later.   FortiOS 7.0.12 and later contains IPS engine 7.0167 as the default IPS Engine. Fixed in IPS Engine version 7.0313 and later.   FortiOS 7.2.5 and later contains IPS engine 7.0314 as the default IPS Engine.   IPS Engine 7.0322 is downloadable from FortiGuard by FortiGate units with a valid subscription running FortiOS 7.2.x. FortiOS 7.4.0 and later contains IPS engine 7.0493 as the default IPS Engine.  
Is CVE-2023-40718 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-40718 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-40718?
CVE-2023-40718 affects Fortinet IPS Engine.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.