Improper certificate validation in Fortinet, Inc products - CVE-2024-31489

 

Improper certificate validation in Fortinet, Inc products - CVE-2024-31489

Published: September 10, 2024


Vulnerability identifier: #VU97117
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31489
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper validation of client-side certificate in ZTA service. A remote attacker can perform Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation.


Affected software

FortiClient (Linux)
FortiClient (macOS)
Fortinet FortiClient for Windows

How to mitigate CVE-2024-31489

Install updates from vendor's website.

FortiClient (Linux) - addressed in versions 7.0.12, 7.2.1
FortiClient (macOS) - addressed in versions 7.0.12, 7.2.5
Fortinet FortiClient for Windows - addressed in versions 7.0.12, 7.2.3

External References

Related Security Bulletins