2023-09-01 14:00:28 +00:00
{
"id" : "CVE-2022-22305" ,
"sourceIdentifier" : "psirt@fortinet.com" ,
"published" : "2023-09-01T12:15:08.363" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T06:46:36.330" ,
2023-11-07 21:03:21 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-09-01 14:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An improper certificate validation vulnerability [CWE-295] in\u00a0FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to\u00a0man-in-the-middle the communication between the listed products and some external peers."
2023-11-07 21:03:21 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de validaci\u00f3n de certificado incorrecta [CWE-295] en FortiManager v7.0.1 y versiones inferiores, v6.4.6 y versiones inferiores; FortiAnalyzer v7.0.2 y versiones inferiores, v6.4.7 y versiones inferiores; FortiOS v6.2.x y v6.0.x; FortiSandbox v4.0.x, 3.2.x y 3.1.x puede permitir a un atacante adyacente a la red y no autenticado interceder en la comunicaci\u00f3n mediante la t\u00e9cnica de man-in-the-middle entre los productos enumerados y algunos peers externos. "
2023-09-01 14:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-09-07 20:00:29 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "psirt@fortinet.com" ,
"type" : "Secondary" ,
2023-09-07 20:00:29 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM" ,
2023-09-07 20:00:29 +00:00
"attackVector" : "ADJACENT_NETWORK" ,
2024-12-08 03:06:42 +00:00
"attackComplexity" : "LOW" ,
2023-09-07 20:00:29 +00:00
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-07 20:00:29 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.8 ,
2023-09-07 20:00:29 +00:00
"impactScore" : 2.5
} ,
2023-09-01 14:00:28 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-09-01 14:00:28 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" ,
"baseScore" : 4.2 ,
"baseSeverity" : "MEDIUM" ,
2023-09-01 14:00:28 +00:00
"attackVector" : "ADJACENT_NETWORK" ,
2024-12-08 03:06:42 +00:00
"attackComplexity" : "HIGH" ,
2023-09-01 14:00:28 +00:00
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-01 14:00:28 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 1.6 ,
2023-09-01 14:00:28 +00:00
"impactScore" : 2.5
}
]
} ,
2023-09-07 20:00:29 +00:00
"weaknesses" : [
{
2024-12-08 03:06:42 +00:00
"source" : "psirt@fortinet.com" ,
"type" : "Secondary" ,
2023-09-07 20:00:29 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-297"
2023-09-07 20:00:29 +00:00
}
]
2023-11-07 21:03:21 +00:00
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-11-07 21:03:21 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-295"
2023-11-07 21:03:21 +00:00
}
]
2023-09-07 20:00:29 +00:00
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.0.0" ,
"versionEndIncluding" : "6.0.12" ,
"matchCriteriaId" : "2318A6AC-AA3E-4604-968C-35A46E79FCB8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2.9" ,
"versionEndIncluding" : "6.4.7" ,
"matchCriteriaId" : "82AA3275-8A1D-43DA-880B-1EFFBD96C29D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D7DC87E0-0C9F-4E65-B96E-7E91F71764AC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortianalyzer:7.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80518C1A-60DB-4CC3-92ED-0C0BDCF2F1C3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8619721-489F-4BE7-BBAC-7D07FB64A8EF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.0.0" ,
"versionEndIncluding" : "6.0.12" ,
"matchCriteriaId" : "8DFFD873-3F9B-41D8-92E6-09F84712BCE1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2.0" ,
"versionEndIncluding" : "6.2.11" ,
"matchCriteriaId" : "67777F42-09E1-4651-807C-325A5F0D8A66"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.4.0" ,
"versionEndIncluding" : "6.4.6" ,
"matchCriteriaId" : "D4EB03A2-7143-407C-B622-03E6AFAF6A78"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8A4E6379-A79E-4135-BAF1-D53E8F56798B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9CF421D9-54D7-47FB-AB11-A556BDB4A372"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "3.0.0" ,
"versionEndIncluding" : "3.0.7" ,
"matchCriteriaId" : "7D1EE4D7-4087-4A4A-9171-F48B1C5915C0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "3.1.0" ,
"versionEndIncluding" : "3.1.5" ,
"matchCriteriaId" : "2C47A3DB-A02A-488D-B0E1-867A19CE43B8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "3.2.0" ,
"versionEndIncluding" : "3.2.4" ,
"matchCriteriaId" : "16BB4915-1330-45E5-887E-AD97C29F500B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:3.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "527BEC13-9EC9-44AB-9F02-C948BDC96558"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:4.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0260B512-77CA-4FE8-A039-D7B287A19BAA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:4.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7D6CCD1A-3412-4A55-88A8-40B227FB00BA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:fortinet:fortisandbox:4.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "51A80522-EBFC-4C3E-BF38-01453CC359F7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.6.10" ,
"versionEndIncluding" : "5.6.14" ,
"matchCriteriaId" : "1728ED99-9A01-4819-B382-EDEF00F97B9D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.0.0" ,
"versionEndIncluding" : "6.0.17" ,
"matchCriteriaId" : "0135464C-532C-430D-A76C-2FCDE4C991D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2.0" ,
"versionEndIncluding" : "6.2.15" ,
"matchCriteriaId" : "7916D6BB-838E-40A0-9C7F-FBE9ECBA0D99"
}
]
}
]
}
] ,
2023-09-01 14:00:28 +00:00
"references" : [
{
"url" : "https://fortiguard.com/psirt/FG-IR-18-292" ,
2023-09-07 20:00:29 +00:00
"source" : "psirt@fortinet.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://fortiguard.com/psirt/FG-IR-18-292" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-09-01 14:00:28 +00:00
}
]
}