Fortinet FortiOS
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*
- <= 7.6.1
- <= 7.4.7
A vulnerability allowing improper certificate validation has been identified in Fortinet FortiOS versions 7.6.1 and prior, as well as 7.4.7 and prior. This vulnerability may enable an EAP-verified remote user to connect through FortiClient using a revoked certificate.
Exploitation of this vulnerability could lead to unauthorized connections being established via FortiClient, using revoked certificates that should not be trusted.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.