CVE-2023-50178: High severity fortinet fortiadc vulnerability
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and various remote servers such as private SDN connectors and FortiToken Cloud.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50178?
CVE-2023-50178 is considered to have a high severity due to its potential to allow remote and unauthenticated attackers to perform Man-in-the-Middle attacks.
How do I fix CVE-2023-50178?
To fix CVE-2023-50178, users should upgrade to the latest patched version of FortiADC as provided by Fortinet.
Which versions of FortiADC are affected by CVE-2023-50178?
FortiADC versions 6.0 through 7.4.0 are affected by CVE-2023-50178, including specific sub-versions.
What type of attack does CVE-2023-50178 facilitate?
CVE-2023-50178 facilitates a Man-in-the-Middle attack due to improper certificate validation.
Is user authentication required to exploit CVE-2023-50178?
No, exploitation of CVE-2023-50178 does not require user authentication, making it more critical.