CVE-2024-33509
published 2024-07-09CVE-2024-33509: An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a…
PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.19%
8.7th percentile
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 6.3.0 < 7.2.2 | 7.2.2 |
| fortinet | fortiweb | 6.3.0 – 6.3.23 | — |
| fortinet | fortiweb | 6.4.0 – 6.4.3 | — |
| fortinet | fortiweb | 7.0.0 – 7.0.10 | — |
| fortinet | fortiweb | 7.2.0 – 7.2.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all ve...
vendor_fortinet·2024-07-09·CVSS 4.8
CVE-2024-33509 [MEDIUM] CWE-295 An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all ve...
FG-IR-22-326: An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all ve...
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).
CVEs: CVE-2024-33509
CWEs: CWE-295
CVSS: 4.8 (medium)
Affected products: FortiWeb
GHSA
GHSA-49fh-c382-5964: An improper certificate validation vulnerability [CWE-295] in FortiWeb 7
ghsa_unreviewed·2024-07-09
CVE-2024-33509 [MEDIUM] CWE-295 GHSA-49fh-c382-5964: An improper certificate validation vulnerability [CWE-295] in FortiWeb 7
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-09
Published