CVE-2022-22305
5.4MEDIUM
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 1 September 2023
Summary
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Affected Version(s)
FortiAnalyzer 7.0.0 <= 7.0.2
FortiAnalyzer 6.4.0 <= 6.4.7
FortiAnalyzer 6.2.0 <= 6.2.11
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database