Description
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiWeb version 7.2.2 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31247 | An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF). |
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-22-326 |
|
History
Mon, 09 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiweb |
|
| CPEs | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortiweb |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T02:36:02.831Z
Reserved: 2024-04-23T14:18:29.831Z
Link: CVE-2024-33509
Updated: 2024-08-02T02:36:02.831Z
Status : Modified
Published: 2024-07-09T16:15:05.950
Modified: 2024-11-21T09:17:02.900
Link: CVE-2024-33509
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD