Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-40590


AnĀ improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.


Published

2025-03-14T15:15:41.630

Last Modified

2025-07-24T18:48:26.017

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiportal < 7.0.9 Yes
Application fortinet fortiportal < 7.2.5 Yes
Application fortinet fortiportal 7.4.0 Yes

References