cbcvebase.
CVE-2023-22642
published 2023-04-11

CVE-2023-22642: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may…

PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.27%
19.4th percentile
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.

Affected

17 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 6.4.0 < 6.4.*6.4.*
fortinetfortianalyzer>= 6.4.8 < 6.4.116.4.11
fortinetfortianalyzer6.4.8 – 6.4.10
fortinetfortianalyzer>= 7.0.0 < 7.0.67.0.6
fortinetfortianalyzer7.0.0 – 7.0.5
fortinetfortianalyzer>= 7.2.0 < 7.2.27.2.2
fortinetfortianalyzer7.2.0 – 7.2.1
fortinetfortiguard
fortinetfortimanager
fortinetfortimanager>= 6.4.0 < 6.4.*6.4.*
fortinetfortimanager>= 6.4.8 < 6.4.116.4.11
fortinetfortimanager6.4.8 – 6.4.10
fortinetfortimanager>= 7.0.0 < 7.0.67.0.6
fortinetfortimanager7.0.0 – 7.0.5
fortinetfortimanager>= 7.2.0 < 7.2.27.2.2
fortinetfortimanager7.2.0 – 7.2.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.