CVE Vulnerabilities

CVE-2022-22306

Improper Certificate Validation

Published: May 24, 2022 | Modified: Jun 06, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.9 LOW
AV:A/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.0.0 (including) 6.0.14 (including)
Fortios Fortinet 6.2.0 (including) 6.2.10 (including)
Fortios Fortinet 6.4.0 (including) 6.4.9 (excluding)
Fortios Fortinet 7.0.0 (including) 7.0.0 (including)

Potential Mitigations

References