Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fg7-gvqp-mhcc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-295