An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54073 An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.
Fixes

Solution

Please upgrade to FortiPortal version 7.4.1 or above Please upgrade to FortiPortal version 7.2.5 or above Please upgrade to FortiPortal version 7.0.9 or above


Workaround

No workaround given by the vendor.

History

Fri, 25 Jul 2025 04:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.0:*:*:*:*:*:*:*

Mon, 14 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00011}

epss

{'score': 0.00014}


Sat, 15 Mar 2025 03:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Mar 2025 00:15:00 +0900

Type Values Removed Values Added
Description An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established between the FortiPortal and those endpoints.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:R'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-03-14T18:02:38.328Z

Reserved: 2024-07-05T11:55:50.011Z

Link: CVE-2024-40590

cve-icon Vulnrichment

Updated: 2025-03-14T18:02:34.346Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-14T15:15:41.630

Modified: 2025-07-24T18:48:26.017

Link: CVE-2024-40590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T20:22:43Z

Weaknesses