AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation
2024-09-10T15:15:15.787
2024-09-20T19:41:19.447
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient | < 7.0.12 | Yes |
Application | fortinet | forticlient | < 7.0.12 | Yes |
Application | fortinet | forticlient | < 7.0.12 | Yes |
Application | fortinet | forticlient | < 7.2.3 | Yes |
Application | fortinet | forticlient | < 7.2.5 | Yes |
Application | fortinet | forticlient | 7.2.0 | Yes |