An improper certificate validation vulnerability in Fortinet FortiOS 7.0.0 - 7.0.13, 7.2.0 - 7.2.6, 7.4.0 - 7.4.1 and 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication channel between the FortiOS device and FortiSwitch.
                
            References
                    | Link | Resource | 
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-301 | Vendor Advisory | 
| https://fortiguard.com/psirt/FG-IR-23-301 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 08:30
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://fortiguard.com/psirt/FG-IR-23-301 - Vendor Advisory | 
21 May 2024, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) An improper certificate validation vulnerability in Fortinet FortiOS 7.0.0 - 7.0.13, 7.2.0 - 7.2.6, 7.4.0 - 7.4.1 and 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication channel between the FortiOS device and FortiSwitch. | 
22 Feb 2024, 15:26
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.4.1:*:*:*:*:*:*:* | |
| First Time | Fortinet Fortinet fortios | |
| References | () https://fortiguard.com/psirt/FG-IR-23-301 - Vendor Advisory | |
| Summary | 
 | 
15 Feb 2024, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-02-15 14:15
Updated : 2024-11-21 08:30
NVD link : CVE-2023-47537
Mitre link : CVE-2023-47537
CVE.ORG link : CVE-2023-47537
JSON object : View
Products Affected
                fortinet
- fortios
CWE
                
                    
                        
                        CWE-295
                        
            Improper Certificate Validation
