cbcvebase.
CVE-2022-22305
published 2023-09-01

CVE-2022-22305: An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below…

PriorityP419medium4.2CVSS 3.1
AVAACHPRNUINSUCLILAN
EPSS
0.48%
40.4th percentile
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer——
fortinetfortianalyzer——
fortinetfortianalyzer——
fortinetfortianalyzer——
fortinetfortianalyzer6.0.0 – 6.0.12—
fortinetfortianalyzer6.2.0 – 6.2.11—
fortinetfortianalyzer6.2.9 – 6.4.7—
fortinetfortianalyzer6.4.0 – 6.4.7—
fortinetfortianalyzer7.0.0 – 7.0.2—
fortinetfortimanager——
fortinetfortimanager——
fortinetfortimanager——
fortinetfortimanager6.0.0 – 6.0.12—
fortinetfortimanager6.2.0 – 6.2.11—
fortinetfortimanager6.4.0 – 6.4.6—
fortinetfortimanager7.0.0 – 7.0.1—
fortinetfortios——
fortinetfortios5.6.10 – 5.6.14—
fortinetfortios6.0.0 – 6.0.17—
fortinetfortios6.2.0 – 6.2.15—
fortinetfortisandbox——
fortinetfortisandbox——
fortinetfortisandbox——
fortinetfortisandbox——
fortinetfortisandbox——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.