Improper Certificate Validation in FortiOS Products by Fortinet
CVE-2022-22306

5.4MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
24 May 2022

Summary

An improper certificate validation vulnerability exists in specific versions of FortiOS, potentially enabling an unauthenticated network-adjacent attacker to conduct man-in-the-middle attacks. This flaw permits interception and manipulation of communications between FortiGate devices and peer systems, including private software-defined networks (SDNs) and external cloud services, posing significant risks to data integrity and confidentiality.

Affected Version(s)

Fortinet FortiOS FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.