CVE-2023-22642
published 2023-04-11CVE-2023-22642: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may…
PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.27%
19.4th percentile
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.4.0 < 6.4.* | 6.4.* |
| fortinet | fortianalyzer | >= 6.4.8 < 6.4.11 | 6.4.11 |
| fortinet | fortianalyzer | 6.4.8 – 6.4.10 | — |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.6 | 7.0.6 |
| fortinet | fortianalyzer | 7.0.0 – 7.0.5 | — |
| fortinet | fortianalyzer | >= 7.2.0 < 7.2.2 | 7.2.2 |
| fortinet | fortianalyzer | 7.2.0 – 7.2.1 | — |
| fortinet | fortiguard | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 6.4.* | 6.4.* |
| fortinet | fortimanager | >= 6.4.8 < 6.4.11 | 6.4.11 |
| fortinet | fortimanager | 6.4.8 – 6.4.10 | — |
| fortinet | fortimanager | >= 7.0.0 < 7.0.6 | 7.0.6 |
| fortinet | fortimanager | 7.0.0 – 7.0.5 | — |
| fortinet | fortimanager | >= 7.2.0 < 7.2.2 | 7.2.2 |
| fortinet | fortimanager | 7.2.0 – 7.2.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert
vendor_fortinet·2023-04-11·CVSS 7.5
CVE-2023-22642 [HIGH] CWE-295 Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert
FG-IR-22-502: Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
CVEs: CVE-2023-22642
CWEs: CWE-295
CVSS: 7.5 (high)
Affected products: FortiAnalyzer, FortiGuard, FortiManager
GHSA
GHSA-4pv6-q257-8q33: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7
ghsa_unreviewed·2023-04-11
CVE-2023-22642 [HIGH] CWE-295 GHSA-4pv6-q257-8q33: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-11
Published