QID 377730

Date Published: 2022-11-03

QID 377730: FortiManager - Improper Certificate Validation Vulnerability (FG-IR-18-292)

An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.

Affected Products:
FortiManager version 7.0.1 and below.
FortiManager version 6.4.6 and below.
FortiAnalyzer version 7.0.2 and below.
FortiAnalyzer version 6.4.7 and below.

QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager.

Vulnerable version may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.

  • CVSS V3 rated as Medium - 5.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-18-292

    Vendor References

    CVEs related to QID 377730

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-18-292 URL Logo www.fortiguard.com/psirt/FG-IR-18-292