CVE Vulnerabilities

CVE-2023-29175

Improper Certificate Validation

Published: Jun 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remoteĀ FortiGuards map server.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
FortiproxyFortinet1.2.0 (including)1.2.13 (including)
FortiproxyFortinet2.0.0 (including)2.0.12 (including)
FortiproxyFortinet7.0.0 (including)7.0.9 (including)
FortiproxyFortinet7.2.0 (including)7.2.3 (including)
FortiosFortinet6.0.0 (including)6.0.17 (including)
FortiosFortinet6.2.0 (including)6.2.15 (including)
FortiosFortinet6.4.0 (including)6.4.13 (including)
FortiosFortinet7.0.0 (including)7.0.11 (excluding)
FortiosFortinet7.2.0 (including)7.2.0 (including)

Potential Mitigations

References