cbcvebase.
CVE-2022-22305
published 2023-09-01

CVE-2022-22305: An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below…

PriorityP419medium4.2CVSS 3.1
AVAACHPRNUINSUCLILAN
EPSS
0.48%
38.6th percentile
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer6.0.0 – 6.0.12
fortinetfortianalyzer6.2.0 – 6.2.11
fortinetfortianalyzer6.2.9 – 6.4.7
fortinetfortianalyzer6.4.0 – 6.4.7
fortinetfortianalyzer7.0.0 – 7.0.2
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager6.0.0 – 6.0.12
fortinetfortimanager6.2.0 – 6.2.11
fortinetfortimanager6.4.0 – 6.4.6
fortinetfortimanager7.0.0 – 7.0.1
fortinetfortios
fortinetfortios5.6.10 – 5.6.14
fortinetfortios6.0.0 – 6.0.17
fortinetfortios6.2.0 – 6.2.15
fortinetfortisandbox
fortinetfortisandbox
fortinetfortisandbox
fortinetfortisandbox
fortinetfortisandbox
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.