CVE-2022-22305: Medium severity fortinet fortianalyzer vulnerability
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22305.
What is the severity level of CVE-2022-22305?
CVE-2022-22305 has a severity level of medium.
Which software versions are affected by CVE-2022-22305?
CVE-2022-22305 affects FortiManager versions 7.0.1 and below, 6.4.6 and below; FortiAnalyzer versions 7.0.2 and below, 6.4.7 and below; FortiOS versions 6.2.x and 6.0.x; FortiSandbox versions 4.0.x, 3.2.x, and 3.1.x.
How can an attacker exploit CVE-2022-22305?
An unauthenticated network adjacent attacker can exploit CVE-2022-22305 to perform a man-in-the-middle attack.
Where can I find more information about CVE-2022-22305?
More information about CVE-2022-22305 can be found at the following link: https://fortiguard.com/psirt/FG-IR-18-292.