Medium severity5.4NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026
CVE-2022-22305
CVE-2022-22305
Description
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.
Affected products
20cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.12
- cpe:2.3:a:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortianalyzer:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:*
- (no CPE)range: <=7.0.2, <=6.4.7
- (no CPE)range: 7.0.0
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.12
- cpe:2.3:a:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:*
- (no CPE)range: <=7.0.1, <=6.4.6
- (no CPE)range: 7.0.0
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: >=3.0.0,<=3.0.7
- cpe:2.3:a:fortinet:fortisandbox:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox:4.0.2:*:*:*:*:*:*:*
- (no CPE)range: 4.0.x, 3.2.x, 3.1.x
- (no CPE)range: 4.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-18-292nvdVendor Advisory
News mentions
0No linked articles in our index yet.