CVE-2024-33509: Medium severity fortinet fortiweb vulnerability
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33509?
CVE-2024-33509 is assessed as a critical vulnerability due to its potential impact on communication security.
How do I fix CVE-2024-33509?
To mitigate CVE-2024-33509, upgrade FortiWeb to version 7.2.2 or later.
What systems are affected by CVE-2024-33509?
CVE-2024-33509 affects FortiWeb versions 7.2.0 through 7.2.1, as well as all versions of 7.0, 6.4, and 6.3.
What attack vector is enabled by CVE-2024-33509?
CVE-2024-33509 allows remote unauthenticated attackers to perform Man-in-the-Middle attacks.
What consequence can result from exploiting CVE-2024-33509?
Exploitation of CVE-2024-33509 may allow attackers to decipher or tamper with the communication channels.