QID 378394
Date Published: 2023-04-13
QID 378394: Fortinet FortiManager and FortiAnalyzer Improper Certificate Validation Vulnerability (FG-IR-22-502)
An improper certificate validation vulnerability in FortiAnalyzer and FortiManager may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert resources.
Affected Products:
FortiAnalyzer version 7.2.0 through 7.2.1
FortiAnalyzer version 7.0.0 through 7.0.5
FortiAnalyzer version 6.4.8 through 6.4.10
FortiManager version 7.2.0 through 7.2.1
FortiManager version 7.0.0 through 7.0.5
FortiManager version 6.4.8 through 6.4.10
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Successful exploitation of this vulnerability may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-502
- FG-IR-22-502 -
www.fortiguard.com/psirt/FG-IR-22-502
CVEs related to QID 378394
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-502 |
|