FORTINET Security Advisory
Published Date: Not specified
Advisory Summary
🛡️🔎 ⚠️ ZTNA Portal Improper Certificate Validation (CWE-295)
Fortinet has highlighted a CWE-295 improper certificate validation vulnerability affecting FortiOS and the FortiProxy Agentless ZTNA portal. The issue is rated CVSSv3: 7.3, and—critically—may enable a remote, unauthenticated attacker to execute a Man-in-the-Middle (MITM) attack on the communication channel between the ZTNA portal and the backend destination website.
### 🧨 What this means for your environment
• MITM risk: An attacker could intercept or manipulate traffic flowing from the ZTNA portal to the protected backend destination.
• Unauthenticated exposure: The lack of authentication requirement increases urgency for perimeter and internet-facing deployments.
• ZTNA trust boundary impact: Compromises the integrity of a core access-control communication path, potentially undermining the security guarantees ZTNA is expected to provide.
### 🚨 Alarms (Where to prioritize)
1) Agentless ZTNA portals that connect to external or high-value backend sites
2) Internet-facing FortiOS / FortiProxy components
3) Any paths where TLS certificate validation is expected to enforce backend identity
- Check Fortinet PSIRT guidance and determine whether your specific FortiOS/FortiProxy version is affected and which fixed releases apply.
- Prioritize remediation for systems handling ZTNA portal traffic to critical destinations.
- Ensure ZTNA backend connections are not relying on weakened trust models or misconfigured CA chains.
- Reduce exposure of ZTNA portal endpoints (tighten network ACLs / restrict inbound reachability).
- Monitor for indicators consistent with MITM behavior (unexpected certificate anomalies, unusual backend TLS sessions, or traffic pattern deviations).
📌 Security Patch / Advisory
-295
Reference: Vendor Advisory