Improper Certificate Validation in FortiOS Products by Fortinet
CVE-2022-22306
5.4MEDIUM
Summary
An improper certificate validation vulnerability exists in specific versions of FortiOS, potentially enabling an unauthenticated network-adjacent attacker to conduct man-in-the-middle attacks. This flaw permits interception and manipulation of communications between FortiGate devices and peer systems, including private software-defined networks (SDNs) and external cloud services, posing significant risks to data integrity and confidentiality.
Affected Version(s)
Fortinet FortiOS FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved