CVE-2023-29175: Fortinet FortiOS
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the vulnerable device and the remote FortiGuard's map server.
Affected products
- Fortinet FortiOS: from 6.0.0, up to and including 6.0.17; from 6.2.0, up to and including 6.2.15; from 6.4.0, up to and including 6.4.13; from 7.0.0, before 7.0.11 (fixed in 7.0.11); version 7.2.0 only
- Fortinet FortiProxy: from 1.2.0, up to and including 1.2.13; from 2.0.0, up to and including 2.0.12; from 7.0.0, up to and including 7.0.9; from 7.2.0, up to and including 7.2.3
Published 2023-06-13. Last modified 2026-06-17.