CVE-2023-22642: Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
Other sources
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet vulnerability?
The vulnerability ID for this Fortinet vulnerability is CVE-2023-22642.
Which products are affected by this vulnerability?
FortiAnalyzer and FortiManager versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, and 6.4.8 through 6.4.10 are affected by this vulnerability.
What is the severity level of CVE-2023-22642?
The severity level of CVE-2023-22642 is high with a severity value of 8.1.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-295.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to perform a Man-in-the-Middle attack on the communication channel between the device and the remote server.