8.1
CVSSv3

CVE-2023-22642

Published: 11/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 up to and including 7.2.1, 7.0.0 up to and including 7.0.5, 6.4.8 up to and including 6.4.10 may allow a remote and unauthenticated malicious user to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortianalyzer

fortinet fortimanager