CVE-2022-22305
published 2023-09-01CVE-2022-22305: An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below…
PriorityP419medium4.2CVSS 3.1
AVAACHPRNUINSUCLILAN
EPSS
0.48%
38.6th percentile
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 6.0.0 – 6.0.12 | — |
| fortinet | fortianalyzer | 6.2.0 – 6.2.11 | — |
| fortinet | fortianalyzer | 6.2.9 – 6.4.7 | — |
| fortinet | fortianalyzer | 6.4.0 – 6.4.7 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.2 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 6.0.0 – 6.0.12 | — |
| fortinet | fortimanager | 6.2.0 – 6.2.11 | — |
| fortinet | fortimanager | 6.4.0 – 6.4.6 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.1 | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 5.6.10 – 5.6.14 | — |
| fortinet | fortios | 6.0.0 – 6.0.17 | — |
| fortinet | fortios | 6.2.0 – 6.2.15 | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Lack of certificate verification when establishing secure connections
vendor_fortinet·2023-09-01·CVSS 5.4
CVE-2022-22305 [MEDIUM] CWE-295 Lack of certificate verification when establishing secure connections
FG-IR-18-292: Lack of certificate verification when establishing secure connections
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
CVEs: CVE-2022-22305
CWEs: CWE-295, CWE-297
CVSS: 5.4 (medium)
Affected products: FortiAnalyzer, FortiManager, FortiOS, FortiSandbox
GHSA
GHSA-r4mc-2xrg-97hv: An improper certificate validation vulnerability [CWE-295] in FortiManager 7
ghsa_unreviewed·2023-09-01
CVE-2022-22305 [MEDIUM] CWE-295 GHSA-r4mc-2xrg-97hv: An improper certificate validation vulnerability [CWE-295] in FortiManager 7
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-01
Published