Executive Risk Summary
"A missing critical step in authentication vulnerability in Fortinet FortiOS and FortiProxy allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid, potentially leading to unauthorized access. This vulnerability affects FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16, as well as FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20."
Operational Audit Arsenal
Manual Verification Required
This is a non-Windows asset (Fortinet). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.
Patch Impact Forecast
Moderate
Internal Work Notes
Technical Intelligence & Operational Utilities • Delivered Weekly