CVE-2024-33509

CVSS V2 None CVSS V3 None
Description
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).
Overview
  • CVE ID
  • CVE-2024-33509
  • Assigner
  • fortinet
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-09T15:33:24.418Z
  • Last Modified Date
  • 2024-07-09T15:33:24.418Z
References
History
Created Old Value New Value Data Type Notes
2024-07-10 13:33:35 Added to TrackCVE