missing digital certificate validation

Summary

An improper certificate validation vulnerability [CWE-295] in Fortiportal when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints. 

Version Affected Solution
FortiPortal 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiPortal 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiPortal 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiPortal 6.0 6.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Jonas Mellander from Fortinet.

Timeline

2024-11-12: Initial publication