CVE-2022-22306
published 2022-05-24CVE-2022-22306: An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a…
PriorityP424medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
EPSS
0.20%
9.5th percentile
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortigate | — | — |
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 6.0.0 – 6.0.14 | — |
| fortinet | fortios | 6.2.0 – 6.2.10 | — |
| fortinet | fortios | >= 6.4.0 < 6.4.9 | 6.4.9 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4v68-66g8-2grg: An improper certificate validation vulnerability [CWE-295] in FortiOS 6
ghsa_unreviewed·2022-05-25
CVE-2022-22306 [MEDIUM] CWE-295 GHSA-4v68-66g8-2grg: An improper certificate validation vulnerability [CWE-295] in FortiOS 6
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
Fortinet
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0...
vendor_fortinet·2022-05-24·CVSS 5.4
CVE-2022-22306 [MEDIUM] CWE-295 An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0...
FG-IR-21-239: An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0...
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
CVEs: CVE-2022-22306
CWEs: CWE-295
CVSS: 5.4 (medium)
Affected products: FortiGate, FortiOS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-24
Published