CVSS3
Attack Vector
ADJACENT
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
Percentile
18.0%
An improper certificate validation vulnerability [CWE-295] inย FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker toย man-in-the-middle the communication between the listed products and some external peers.
Vendor | Product | Version | CPE |
---|---|---|---|
fortinet | fortianalyzer | * | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* |
fortinet | fortianalyzer | 7.0.0 | cpe:2.3:a:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:* |
fortinet | fortianalyzer | 7.0.1 | cpe:2.3:a:fortinet:fortianalyzer:7.0.1:*:*:*:*:*:*:* |
fortinet | fortianalyzer | 7.0.2 | cpe:2.3:a:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:* |
fortinet | fortimanager | * | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
fortinet | fortimanager | 7.0.0 | cpe:2.3:a:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:* |
fortinet | fortimanager | 7.0.1 | cpe:2.3:a:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:* |
fortinet | fortisandbox | * | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* |
fortinet | fortisandbox | 3.0.1 | cpe:2.3:a:fortinet:fortisandbox:3.0.1:*:*:*:*:*:*:* |
fortinet | fortisandbox | 4.0.0 | cpe:2.3:a:fortinet:fortisandbox:4.0.0:*:*:*:*:*:*:* |