CVE Vulnerabilities

CVE-2022-22305

Improper Certificate Validation

Published: Sep 01, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 6.0.0 (including) 6.0.12 (including)
Fortianalyzer Fortinet 6.2.9 (including) 6.4.7 (including)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.0 (including)
Fortianalyzer Fortinet 7.0.1 (including) 7.0.1 (including)
Fortianalyzer Fortinet 7.0.2 (including) 7.0.2 (including)
Fortimanager Fortinet 6.0.0 (including) 6.0.12 (including)
Fortimanager Fortinet 6.2.0 (including) 6.2.11 (including)
Fortimanager Fortinet 6.4.0 (including) 6.4.6 (including)
Fortimanager Fortinet 7.0.0 (including) 7.0.0 (including)
Fortimanager Fortinet 7.0.1 (including) 7.0.1 (including)
Fortisandbox Fortinet 3.0.0 (including) 3.0.7 (including)
Fortisandbox Fortinet 3.1.0 (including) 3.1.5 (including)
Fortisandbox Fortinet 3.2.0 (including) 3.2.4 (including)
Fortisandbox Fortinet 3.0.1 (including) 3.0.1 (including)
Fortisandbox Fortinet 4.0.0 (including) 4.0.0 (including)
Fortisandbox Fortinet 4.0.1 (including) 4.0.1 (including)
Fortisandbox Fortinet 4.0.2 (including) 4.0.2 (including)
Fortios Fortinet 5.6.10 (including) 5.6.14 (including)
Fortios Fortinet 6.0.0 (including) 6.0.17 (including)
Fortios Fortinet 6.2.0 (including) 6.2.15 (including)

Potential Mitigations

References