Improper Certificate Validation in Fortinet, Inc products - CVE-2022-22305
Published: June 8, 2022
Vulnerability identifier: #VU64051
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22305
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation. A remote attacker with ability to intercept traffic can perform MitM attack against the affected products and certain external peers.
Affected software
FortiSandbox
FortiOS
FortiManager
FortiAnalyzer
FortiOS
FortiManager
FortiAnalyzer
How to mitigate CVE-2022-22305
Install updates from vendor's website.
FortiSandbox - update to 4.2.0
FortiOS - addressed in versions 6.4.0, 7.0.0
FortiManager - addressed in versions 6.4.7, 7.0.2
FortiAnalyzer - addressed in versions 6.4.8, 7.0.3
FortiOS - addressed in versions 6.4.0, 7.0.0
FortiManager - addressed in versions 6.4.7, 7.0.2
FortiAnalyzer - addressed in versions 6.4.8, 7.0.3