QID 44096

Date Published: 2023-08-09

QID 44096: FortiOS - Improper Verification Of Chain Of Trust of User Certificate Vulnerability (FG-IR-21-018)

FortiOS is vulnerable to chain of trust vulnerability in FortiGate SSL-VPN.

Affected Versions:
FortiOS Versions 6.4.0 to 6.4.4

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful attack may allow an LDAP user to connect to VPN with any certificate that is signed by a trusted Certificate Authority.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-018
    Vendor References

    CVEs related to QID 44096

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-018 URL Logo www.fortiguard.com/psirt/FG-IR-21-018