CVE Vulnerabilities

CVE-2024-31489

Improper Certificate Validation

Published: Sep 10, 2024 | Modified: Sep 20, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 7.0.0 (including) 7.0.12 (excluding)
Forticlient Fortinet 7.2.0 (including) 7.2.3 (excluding)
Forticlient Fortinet 7.2.0 (including) 7.2.5 (excluding)
Forticlient Fortinet 7.2.0 (including) 7.2.0 (including)

Potential Mitigations

References