QID 44096
Date Published: 2023-08-09
QID 44096: FortiOS - Improper Verification Of Chain Of Trust of User Certificate Vulnerability (FG-IR-21-018)
FortiOS is vulnerable to chain of trust vulnerability in FortiGate SSL-VPN.
Affected Versions:
FortiOS Versions 6.4.0 to 6.4.4
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful attack may allow an LDAP user to connect to VPN with any certificate that is signed by a trusted Certificate Authority.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-018
Vendor References
- FG-IR-21-018 -
www.fortiguard.com/psirt/FG-IR-21-018
CVEs related to QID 44096
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-018 |
|