CVE Vulnerabilities

CVE-2023-47537

Improper Certificate Validation

Published: Feb 15, 2024 | Modified: May 21, 2024
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper certificate validation vulnerability in Fortinet FortiOS 7.0.0 - 7.0.13, 7.2.0 - 7.2.6, 7.4.0 - 7.4.1 and 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication channel between the FortiOS device and FortiSwitch.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 7.0.0 (including) 7.0.14 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.6 (including)
Fortios Fortinet 7.4.0 (including) 7.4.0 (including)
Fortios Fortinet 7.4.1 (including) 7.4.1 (including)

Potential Mitigations

References