[FortiWeb] Lack of client-side certificate validation when establishing secure connections

Summary

An improper certificate validation vulnerability [CWE-295] in FortiWeb may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication channel between the device and different endpoints used to fetch data for Web Application Firewall (WAF).

Version Affected Solution
FortiWeb 7.6 Not affected Not Applicable
FortiWeb 7.4 Not affected Not Applicable
FortiWeb 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 6.4 all versions Migrate to a fixed release
FortiWeb 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Wilfried Djettchou of Fortinet Product Security team.

Timeline

2024-07-09: Initial publication