QID 44095
Date Published: 2023-08-15
QID 44095: FortiOS - Improper Certificate Validation Vulnerability (FG-IR-22-468)
FortiOS is vulnerable to Man-in-the-Middle attack on the communication channel between the vulnerable device and the remote FortiGuard's map server.
Affected Versions:
FortiOS versions 7.2.0
FortiOS versions 7.0.0 through 7.0.10
FortiOS 6.4 all versions
FortiOS 6.2 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable versions of FortiOS may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-468
Vendor References
- FG-IR-22-468 -
www.fortiguard.com/psirt/FG-IR-22-468
CVEs related to QID 44095
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-468 |
|