FG-IR-24-046: No certificate name verification for fgfm connection
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice and FortiWeb may allow an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-046?
The severity of FG-IR-24-046 is considered high due to improper restrictions allowing possible man-in-the-middle attacks.
How do I fix FG-IR-24-046?
To fix FG-IR-24-046, upgrade affected Fortinet products to the recommended versions specified by Fortinet.
What products are affected by FG-IR-24-046?
FG-IR-24-046 affects various versions of FortiOS, FortiManager, FortiAnalyzer, FortiWeb, FortiProxy, and FortiVoice.
Who can exploit FG-IR-24-046?
An unauthenticated attacker positioned in a man-in-the-middle role can exploit FG-IR-24-046.
What is the nature of the vulnerability FG-IR-24-046?
FG-IR-24-046 is characterized as an improper restriction of communication channels to intended endpoints.