Improper Certificate Validation in FortiManager and FortiAnalyzer - CVE-2023-22642
Published: April 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation when establishing a secure connection with FortiGuard to download outbreakalerts. A remote attacker can perform MitM attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
Affected software
FortiAnalyzer
How to mitigate CVE-2023-22642
FortiAnalyzer - addressed in versions 6.4.11, 7.0.6, 7.2.2