Lucene search

K
nvd[email protected]NVD:CVE-2022-22305
HistorySep 01, 2023 - 12:15 p.m.

CVE-2022-22305

2023-09-0112:15:08
CWE-295
CWE-297
web.nvd.nist.gov
3
certificate validation
fortimanager
fortianalyzer
fortios
fortisandbox
mitm attack
network security
vulnerability
cwe-295

CVSS3

4.2

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

18.0%

An improper certificate validation vulnerability [CWE-295] inย FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker toย man-in-the-middle the communication between the listed products and some external peers.

Affected configurations

Nvd
Node
fortinetfortianalyzerRange6.0.0โ€“6.0.12
OR
fortinetfortianalyzerRange6.2.9โ€“6.4.7
OR
fortinetfortianalyzerMatch7.0.0
OR
fortinetfortianalyzerMatch7.0.1
OR
fortinetfortianalyzerMatch7.0.2
OR
fortinetfortimanagerRange6.0.0โ€“6.0.12
OR
fortinetfortimanagerRange6.2.0โ€“6.2.11
OR
fortinetfortimanagerRange6.4.0โ€“6.4.6
OR
fortinetfortimanagerMatch7.0.0
OR
fortinetfortimanagerMatch7.0.1
OR
fortinetfortisandboxRange3.0.0โ€“3.0.7
OR
fortinetfortisandboxRange3.1.0โ€“3.1.5
OR
fortinetfortisandboxRange3.2.0โ€“3.2.4
OR
fortinetfortisandboxMatch3.0.1
OR
fortinetfortisandboxMatch4.0.0
OR
fortinetfortisandboxMatch4.0.1
OR
fortinetfortisandboxMatch4.0.2
OR
fortinetfortiosRange5.6.10โ€“5.6.14
OR
fortinetfortiosRange6.0.0โ€“6.0.17
OR
fortinetfortiosRange6.2.0โ€“6.2.15
VendorProductVersionCPE
fortinetfortianalyzer*cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
fortinetfortianalyzer7.0.0cpe:2.3:a:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:*
fortinetfortianalyzer7.0.1cpe:2.3:a:fortinet:fortianalyzer:7.0.1:*:*:*:*:*:*:*
fortinetfortianalyzer7.0.2cpe:2.3:a:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:*
fortinetfortimanager*cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
fortinetfortimanager7.0.0cpe:2.3:a:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:*
fortinetfortimanager7.0.1cpe:2.3:a:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:*
fortinetfortisandbox*cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
fortinetfortisandbox3.0.1cpe:2.3:a:fortinet:fortisandbox:3.0.1:*:*:*:*:*:*:*
fortinetfortisandbox4.0.0cpe:2.3:a:fortinet:fortisandbox:4.0.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS3

4.2

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

18.0%