CVE-2024-40590

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager de

Severity
Medium 4.4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
4.9th percentile
Discovered by
Not disclosed
Published
Mar 14, 2025
Assigned by fortinet

Description

An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiPortal

Vendor remediation

Please upgrade to FortiPortal version 7.4.1 or above Please upgrade to FortiPortal version 7.2.5 or above Please upgrade to FortiPortal version 7.0.9 or above