Mastodon Mastodon Mastodon Mastodon

Certificate validation vulnerability in FortiOS and FortiProxy allows interception of ZTNA portal traffic

Photo of author

CyberSecureFox Editorial Team

Published:

Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS and FortiProxy. The vendor has rated the vulnerability at CVSSv3 7.3 (high severity). According to the advisory, it allows a remote, unauthenticated attacker to carry out a Man-in-the-Middle (MITM) attack on the communication channel between the ZTNA portal and the target backend server. Organizations using agentless ZTNA through FortiOS or FortiProxy should immediately refer to the full text of the advisory to determine affected versions and available updates.

Technical details of the vulnerability

The vulnerability belongs to the CWE-295 — Improper Certificate Validation class. The core issue is that the agentless ZTNA portal in FortiOS and FortiProxy does not sufficiently validate certificates when establishing a connection to backend servers — the web applications to which the ZTNA portal proxies user traffic.

This means that an attacker who can position themselves between the ZTNA portal and the target backend server can intercept, read, and modify transmitted data. It is important to emphasize that, according to the Fortinet advisory, no authentication is required to exploit this issue.

Affected products, according to the advisory:

  • FortiOS — the operating system of FortiGate devices
  • FortiProxy — Fortinet’s proxy solution

The specific ranges of affected versions and the version numbers of fixed releases are not stated in the provided text of the advisory. A CVE identifier is also not published in the publicly available portion of the advisory. The status of active exploitation is currently unknown.

Impact assessment

The agentless ZTNA portal is a component of a Zero Trust Network Access architecture that allows users to access internal web applications via a browser without installing an agent on the endpoint. The portal acts as an intermediary between the user and the backend server, and it is this segment — between the portal and the backend — that is vulnerable.

A successful MITM attack on this segment potentially allows an attacker to:

  • Intercept data transmitted between the portal and protected applications, including credentials and sensitive information
  • Modify backend server responses by injecting malicious content
  • Compromise sessions of users working through the ZTNA portal

The highest risk is to organizations that have deployed agentless ZTNA access to critical internal applications, especially in scenarios where the network path between FortiGate/FortiProxy and the backend servers traverses untrusted network segments.

Recommendations

  • Check whether your infrastructure uses agentless ZTNA mode via FortiOS or FortiProxy
  • Refer to the full FG-IR-26-174 advisory on the FortiGuard PSIRT portal for information about affected versions and available updates
  • Monitor updates on the Fortinet PSIRT advisory page, as the advisory may be supplemented with details on affected versions and fixes
  • As a temporary measure, evaluate additional network segmentation between the ZTNA portal and backend servers to minimize the attack surface on this segment

We have previously covered critical vulnerabilities in Fortinet products — the current advisory confirms that the FortiOS and FortiProxy product lines remain subject to regular security fixes.

The CVSSv3 7.3 score indicates high severity, and the absence of an authentication requirement lowers the barrier to entry for an attacker. Organizations using agentless ZTNA should give priority to checking whether the advisory applies to their FortiOS and FortiProxy versions and plan to update as soon as the vendor releases fixed versions.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.