QID 44050
Date Published: 2023-05-31
QID 44050: FortiOS - Improper Certificate Validation Vulnerability (FG-IR-18-292) (Unauthenticated Check)
An improper certificate validation vulnerability [CWE-295] in FortiOS may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Affected Products:
FortiOS versions 6.2.x
FortiOS versions 6.0.x
FortiOS versions 5.6.x
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiOS.
Vulnerable version may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-18-292
Vendor References
- FG-IR-18-292 -
www.fortiguard.com/psirt/FG-IR-18-292
CVEs related to QID 44050
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-18-292 |
|