#VU75010 Improper Certificate Validation in FortiAnalyzer and FortiManager - CVE-2023-22642
Published: April 12, 2023
FortiAnalyzer
FortiManager
Fortinet, Inc
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation when establishing a secure connection with FortiGuard to download outbreakalerts. A remote attacker can perform MitM attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.