According to SAM Seamless Network, over 200,000 businesses are using Fortigate VPN with default settings. This choice could allow an attacker to present a valid SSL certificate and carry out man-in-the-middle (MitM) attacks on employees connections. The Fortigate SSL-VPN client only verifies that the CA was issued by Fortigate (or another trusted CA), therefore an attacker can easily present a certificate issued to a different Fortigate router without raising any flags. Fortinet has no plans to address the vulnerability.”]
Source: https://securityaffairs.co/wordpress/108737/hacking/fortigate-vpn-attacks.html

