QID 43981
Date Published: 2023-02-22
QID 43981: Fortinet FortiGate FortiOS Man-in-the-Middle (MITM) Attack Vulnerability (FG-IR-22-257)
An improper certificate validation vulnerability in FortiOS may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS )
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.7
FortiOS version 6.4 all versions
FortiOS version 6.2 all versions
FortiOS version 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of this vulnerability may allow an authenticated attacker may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS )
- FG-IR-22-257 -
www.fortiguard.com/psirt/FG-IR-22-257
CVEs related to QID 43981
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-257 |
|