CVE-2023-22642

CVSS V2 None CVSS V3 None
Description
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
Overview
  • CVE ID
  • CVE-2023-22642
  • Assigner
  • psirt@fortinet.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-11T17:15:08
  • Last Modified Date
  • 2023-04-18T14:35:32
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 1 OR 6.4.8 6.4.11
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 1 OR 7.0.0 7.0.6
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 1 OR 7.2.0 7.2.2
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 1 OR 6.4.8 6.4.11
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 1 OR 7.0.0 7.0.6
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 1 OR 7.2.0 7.2.2
References
Reference URL Reference Tags
https://fortiguard.com/psirt/FG-IR-22-502
History
Created Old Value New Value Data Type Notes
2023-04-17 04:31:32 Added to TrackCVE
2023-04-17 17:00:49 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-04-18 15:00:18 2023-04-18T14:35:32 CVE Modified Date updated
2023-04-18 15:00:18 Undergoing Analysis Analyzed Vulnerability Status updated
2023-04-18 15:00:19 Weakness Enumeration new
2023-04-18 15:00:22 CPE Information updated