Improper Certificate Validation Vulnerability May Allow Unauthenticated MITM Attack on SAML SSO Feature

CVE-2022-45856

5.9MEDIUM

Key Information

Vendor
Fortinet
Status
ForticlientiOS
Forticlientandroid
Forticlientmac
Forticlientlinux
Vendor
CVE Published:
10 September 2024

Summary

An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientAndroid 6.4 all versions, 7.0 all versions, 7.2.0 and FortiClientiOS 5.6 all versions, 6.0.0 through 6.0.1, 7.0.0 through 7.0.6 SAML SSO feature may allow an unauthenticated attacker to man-in-the-middle the communication between the FortiClient and  both the service provider and the identity provider.

Affected Version(s)

FortiClientiOS <= 7.0.6

FortiClientiOS <= 7.0.1

FortiClientiOS <= 6.0.1

Refferences

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.