Impact
The vulnerability is an improper validation of certificates that allows a host mismatch to be accepted, which can enable attackers to obtain sensitive information from the device. The weakness is identified as CWE‑297, related to improper certificate validation.
Affected Systems
Affected products are FortiOS versions 7.6.1 through 7.6.6 and FortiProxy versions 7.6.2 through 7.6.6. Fortinet recommends upgrading to FortiOS 8.0.0 or 7.6.7 and FortiProxy 8.0.0 or 7.6.7. FortiSASE version 26.2.2 has already been remediated and requires no action.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, but the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack vector is not explicitly documented; the description implies that an attacker could trigger the flaw via remote interaction involving certificate handling, potentially over the network. Consequently, the risk remains significant if the affected firmware or appliance remains unpatched.
OpenCVE Enrichment