CVE-2024-40590

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager de

Severity
Medium 4.4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
5.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 14, 2025
Assigned by fortinet

Description

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPortal

Credit

Internally discovered and reported by Jonas Mellander from Fortinet.

Vendor remediation

Please upgrade to FortiPortal version 7.4.1 or above Please upgrade to FortiPortal version 7.2.5 or above Please upgrade to FortiPortal version 7.0.9 or above

Something wrong here?