Description
AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
E
Physical
RL
Unchanged
RC
Changed
Affected products
- fortinet / forticlientems7.0.0 – 7.0.13
- fortinet / forticlientlinux7.0.0 – 7.0.11
- fortinet / forticlientlinux7.2.0 – 7.2.0
- fortinet / forticlientmac7.0.0 – 7.0.11
- fortinet / forticlientmac7.2.0 – 7.2.4
- fortinet / forticlientwindows7.2.0 – 7.2.2
- fortinet / forticlientwindows7.0.0 – 7.0.11
References
- VENDOR_ADVISORYhttps://fortiguard.fortinet.com/psirt/FG-IR-22-282