CVE-2023-22642
CVSS V2 None
CVSS V3 None
Description
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
Overview
- CVE ID
- CVE-2023-22642
- Assigner
- psirt@fortinet.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-04-11T17:15:08
- Last Modified Date
- 2023-04-18T14:35:32
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | 1 | OR | 6.4.8 | 6.4.11 |
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | 1 | OR | 7.0.0 | 7.0.6 |
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | 1 | OR | 7.2.0 | 7.2.2 |
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | 1 | OR | 6.4.8 | 6.4.11 |
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | 1 | OR | 7.0.0 | 7.0.6 |
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | 1 | OR | 7.2.0 | 7.2.2 |
References
Reference URL | Reference Tags |
---|---|
https://fortiguard.com/psirt/FG-IR-22-502 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-22642 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22642 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 04:31:32 | Added to TrackCVE | |||
2023-04-17 17:00:49 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2023-04-18 15:00:18 | 2023-04-18T14:35:32 | CVE Modified Date | updated | |
2023-04-18 15:00:18 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-04-18 15:00:19 | Weakness Enumeration | new | ||
2023-04-18 15:00:22 | CPE Information | updated |