QID 44068
Date Published: 2023-06-21
QID 44068: Fortinet FortiOS Information Disclosure Vulnerability (CVE-2023-29175)
An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remote FortiGuard's map server.
Affected Versions:
FortiOS 7.2.0
FortiOS 7.0.0 through 7.0.10
FortiOS 6.4 all versions
FortiOS 6.2 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID also contains banner based detection .
Successful exploitation of the vulnerability may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-468
Vendor References
- FG-IR-22-468 -
www.fortiguard.com/psirt/FG-IR-22-468
CVEs related to QID 44068
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-468 |
|