CVE Vulnerabilities

CVE-2023-22642

Improper Certificate Validation

Published: Apr 11, 2023 | Modified: Nov 07, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 6.4.8 (including) 6.4.11 (excluding)
Fortianalyzer Fortinet 7.0.0 (including) 7.0.6 (excluding)
Fortianalyzer Fortinet 7.2.0 (including) 7.2.2 (excluding)
Fortimanager Fortinet 6.4.8 (including) 6.4.11 (excluding)
Fortimanager Fortinet 7.0.0 (including) 7.0.6 (excluding)
Fortimanager Fortinet 7.2.0 (including) 7.2.2 (excluding)

Potential Mitigations

References