QID 44034

Date Published: 2023-05-31

QID 44034: FortiOS Lack of Certificate Verification Vulnerability (FG-IR-21-239) (Unauthenticated Check)

An improper certificate validation vulnerability [CWE-295] in FortiOS may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.

Affected Products:
FortiOS version 6.0.0 through 6.0.14
FortiOS version 6.2.0 through 6.2.10
FortiOS version 6.4.0 through 6.4.8
FortiOS version 7.0.0

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable FortiOS may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Low - 2.9 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-239

    Vendor References

    CVEs related to QID 44034

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-239 URL Logo www.fortiguard.com/psirt/FG-IR-21-239