Executive brief
A security flaw exists in Fortinet's Zero Trust Network Access (ZTNA) proxy, a component used to securely connect remote users to internal applications. An attacker positioned on the same local network as the device could intercept and modify encrypted traffic between users and the proxy. This could lead to the exposure of sensitive information or unauthorized tampering with corporate data.
Technical details
The vulnerability (CWE-297) is caused by improper validation of certificates where the host mismatch is not correctly verified within the ZTNA proxy component of FortiOS and FortiProxy. An unauthenticated attacker located in an adjacent network (Man-in-the-Middle position) can exploit this to intercept, decrypt, or modify traffic intended for the ZTNA proxy. The attack requires a high complexity (AC:H) as the attacker must successfully position themselves to intercept the traffic. Fortinet has released patches for FortiOS (7.6.3, 7.4.9) and FortiProxy (7.6.2, 7.4.9) to address this issue.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions
Timeline
- 2025-10-14: disclosed: Initial publication by Fortinet
- 2025-10-14: advisory: FortiGuard Labs advisory FG-IR-24-457 published