Improper Certificate Validation Vulnerability May Allow Unauthenticated MITM Attack on SAML SSO Feature
CVE-2022-45856
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2022-45856?
An improper certificate validation vulnerability exists in FortiClient products, potentially enabling an unauthenticated attacker to intercept and manipulate communications between FortiClient and both service providers and identity providers. This vulnerability impacts various platforms including Windows, Mac, Linux, Android, and iOS across multiple versions. Proper validation of certificates is critical to prevent man-in-the-middle attacks, which could lead to unauthorized information exposure and loss of data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiClientAndroid 7.2.0
FortiClientAndroid 7.0.6 <= 7.0.7
FortiClientAndroid 7.0.2 <= 7.0.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved