<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-502</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-04-11T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-04-11T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-04-11T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiManager version 7.2.0 through 7.2.1FortiManager version 7.0.0 through 7.0.6FortiManager version 6.4.8 through 6.4.10FortiManager 6.2 all versions are not affectedFortiAnalyzer version 7.2.0 through 7.2.1FortiAnalyzer version 7.0.0 through 7.0.6FortiAnalyzer version 6.4.8 through 6.4.10FortiAnalyzer 6.2 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiManager version 7.2.2 or abovePlease upgrade to FortiManager version 7.0.6 or abovePlease upgrade to FortiManager version 6.4.11 or abovePlease upgrade to FortiAnalyzer version 7.2.2 or abovePlease upgrade to FortiAnalyzer version 7.0.6 or abovePlease upgrade to FortiAnalyzer version 6.4.11 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Wilfried Djettchou of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiAnalyzer" Type="Product Name">
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.1">FortiAnalyzer 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.2.0">FortiAnalyzer 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.6">FortiAnalyzer 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.5">FortiAnalyzer 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.4">FortiAnalyzer 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.3">FortiAnalyzer 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.2">FortiAnalyzer 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.1">FortiAnalyzer 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-7.0.0">FortiAnalyzer 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.10">FortiAnalyzer 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.9">FortiAnalyzer 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiAnalyzer-6.4.8">FortiAnalyzer 6.4.8</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiManager" Type="Product Name">
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.1">FortiManager 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.2.0">FortiManager 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.6">FortiManager 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.5">FortiManager 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.4">FortiManager 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.3">FortiManager 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.2">FortiManager 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.1">FortiManager 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiManager-7.0.0">FortiManager 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.10">FortiManager 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.9">FortiManager 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiManager-6.4.8">FortiManager 6.4.8</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert</Title>
        <cvrf:CVE>CVE-2023-22642</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiAnalyzer-7.2.1</ProductID>
                <ProductID>FortiAnalyzer-7.2.0</ProductID>
                <ProductID>FortiAnalyzer-7.0.6</ProductID>
                <ProductID>FortiAnalyzer-7.0.5</ProductID>
                <ProductID>FortiAnalyzer-7.0.4</ProductID>
                <ProductID>FortiAnalyzer-7.0.3</ProductID>
                <ProductID>FortiAnalyzer-7.0.2</ProductID>
                <ProductID>FortiAnalyzer-7.0.1</ProductID>
                <ProductID>FortiAnalyzer-7.0.0</ProductID>
                <ProductID>FortiAnalyzer-6.4.10</ProductID>
                <ProductID>FortiAnalyzer-6.4.9</ProductID>
                <ProductID>FortiAnalyzer-6.4.8</ProductID>
                <ProductID>FortiManager-7.2.1</ProductID>
                <ProductID>FortiManager-7.2.0</ProductID>
                <ProductID>FortiManager-7.0.6</ProductID>
                <ProductID>FortiManager-7.0.5</ProductID>
                <ProductID>FortiManager-7.0.4</ProductID>
                <ProductID>FortiManager-7.0.3</ProductID>
                <ProductID>FortiManager-7.0.2</ProductID>
                <ProductID>FortiManager-7.0.1</ProductID>
                <ProductID>FortiManager-7.0.0</ProductID>
                <ProductID>FortiManager-6.4.10</ProductID>
                <ProductID>FortiManager-6.4.9</ProductID>
                <ProductID>FortiManager-6.4.8</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.8</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-502</URL>
                <Description>Lack of client-side certificate validation when establishing secure connections with FortiGuard to download outbreakalert</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>