CVE-2022-22306: Medium severity fortios vulnerability
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22306?
CVE-2022-22306 has a high severity rating due to the potential for man-in-the-middle attacks.
How do I fix CVE-2022-22306?
To fix CVE-2022-22306, update FortiOS to a version that is not affected, specifically above 6.0.14, 6.2.10, or 6.4.8.
Who is affected by CVE-2022-22306?
CVE-2022-22306 affects users of FortiOS versions 6.0.0 to 6.0.14, 6.2.0 to 6.2.10, 6.4.0 to 6.4.8, and 7.0.0.
What types of attacks can result from CVE-2022-22306?
CVE-2022-22306 may allow an unauthenticated attacker to intercept and manipulate network traffic.
Is CVE-2022-22306 a zero-day vulnerability?
CVE-2022-22306 is not classified as a zero-day vulnerability since it has been publicly disclosed and a patch is available.