FG-IR-22-468: Lack of certificate verification when establishing secure connections
An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remote FortiGuard's map server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-468?
The severity of FG-IR-22-468 is classified as critical due to the potential for a remote unauthenticated attacker to execute a Man-in-the-Middle attack.
How do I fix FG-IR-22-468?
To fix FG-IR-22-468, it is recommended to upgrade FortiOS or FortiProxy to the latest version that addresses this certificate validation vulnerability.
What devices are affected by FG-IR-22-468?
FG-IR-22-468 affects Fortinet FortiOS and FortiProxy devices.
Can FG-IR-22-468 be exploited remotely?
Yes, FG-IR-22-468 can be exploited remotely by an unauthenticated attacker.
What type of attack does FG-IR-22-468 allow?
FG-IR-22-468 allows for a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remote FortiGuard's map server.