CVE Vulnerabilities

CVE-2023-29175

Improper Certificate Validation

Published: Jun 13, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remoteĀ FortiGuards map server.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Fortiproxy Fortinet 1.2.0 (including) 1.2.13 (including)
Fortiproxy Fortinet 2.0.0 (including) 2.0.12 (including)
Fortiproxy Fortinet 7.0.0 (including) 7.0.9 (including)
Fortiproxy Fortinet 7.2.0 (including) 7.2.3 (including)
Fortios Fortinet 6.0.0 (including) 6.0.17 (including)
Fortios Fortinet 6.2.0 (including) 6.2.15 (including)
Fortios Fortinet 6.4.0 (including) 6.4.13 (including)
Fortios Fortinet 7.0.0 (including) 7.0.11 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.0 (including)

Potential Mitigations

References