CVE-2023-47537Improper Certificate Validation in Fortinet Fortios

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 75.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15

Description

An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication channel between the FortiOS device and FortiSwitch.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5

Affected Packages2 packages

NVDfortinet/fortios7.0.07.0.14+3
CVEListV5fortinet/fortios7.4.07.4.1+3

🔴Vulnerability Details

2
CVEList
CVE-2023-47537: An improper certificate validation vulnerability in Fortinet FortiOS 72024-02-15
GHSA
GHSA-37rj-769r-rwrv: An improper certificate validation vulnerability in Fortinet FortiOS 72024-02-15

📋Vendor Advisories

1
Fortinet
Fortilink lack of certificate validation2024-02-15
CVE-2023-47537 — Improper Certificate Validation | cvebase