Home

Description

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.

PUBLISHED Reserved 2022-01-03 | Published 2022-05-24 | Updated 2024-10-22 | Assigner fortinet




MEDIUM: 5.4CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:U/RC:R

Problem types

Information disclosure

Product status

FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0
affected

References

fortiguard.com/psirt/FG-IR-21-239

fortiguard.com/psirt/FG-IR-21-239

cve.org (CVE-2022-22306)

nvd.nist.gov (CVE-2022-22306)