PT-2023-13735 · Fortinet · Fortiproxy+1
Published
2023-02-16
·
Updated
2023-02-24
·
CVE-2022-39948
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.2.0 through 7.2.3
FortiOS versions 7.0.0 through 7.0.7
FortiOS version 6.4 and earlier
FortiOS version 6.2 and earlier
FortiOS version 6.0 and earlier
FortiProxy versions 7.0.0 through 7.0.6
FortiProxy version 2.0 and earlier
FortiProxy version 1.2 and earlier
Description
The issue is related to improper certificate validation, which may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds. This attack is possible when the remote servers are configured as Fabric connectors in FortiOS/FortiProxy.
Recommendations
For FortiOS versions 7.2.0 through 7.2.3, update to a version outside of this range to resolve the issue.
For FortiOS versions 7.0.0 through 7.0.7, update to a version outside of this range to resolve the issue.
For FortiOS version 6.4 and earlier, update to a version later than 6.4 to resolve the issue.
For FortiOS version 6.2 and earlier, update to a version later than 6.2 to resolve the issue.
For FortiOS version 6.0 and earlier, update to a version later than 6.0 to resolve the issue.
For FortiProxy versions 7.0.0 through 7.0.6, update to a version outside of this range to resolve the issue.
For FortiProxy version 2.0 and earlier, update to a version later than 2.0 to resolve the issue.
For FortiProxy version 1.2 and earlier, update to a version later than 1.2 to resolve the issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortiproxy