Description
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27452 | An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-21-239 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:56:45.562Z
Reserved: 2022-01-03T00:00:00.000Z
Link: CVE-2022-22306
Updated: 2024-08-03T03:07:50.421Z
Status : Modified
Published: 2022-05-24T15:15:07.707
Modified: 2024-11-21T06:46:36.470
Link: CVE-2022-22306
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD