[FortiADC] Lack of client-side certificate validation when establishing secure connections with public SDN connectors

Summary

An improper certificate validation vulnerability [CWE-295] in FortiADC may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and public SDN connectors.

Version Affected Solution
FortiADC 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiADC 7.2 7.2 all versions Migrate to a fixed release
FortiADC 7.1 7.1 all versions Migrate to a fixed release
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 Not affected Not Applicable
FortiADC 6.1 Not affected Not Applicable
FortiADC 6.0 Not affected Not Applicable
FortiADC 5.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Wilfried Djettchou of Fortinet Product Security team.

Timeline

2024-07-09: Initial publication