[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-4669Date: (C)2013-06-25   (M)2024-01-23


FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with an SSL session after determining that the server's X.509 certificate is invalid, which allows man-in-the-middle attackers to obtain sensitive information by leveraging a password transmission that occurs before the user warning about the certificate problem.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.4
Exploit Score: 4.9
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.html
BID-59604
http://objectif-securite.ch/forticlient_bulletin.php
http://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/

CPE    5
cpe:/o:apple:mac_os_x
cpe:/a:fortinet:forticlient
cpe:/o:linux:linux_kernel
cpe:/o:google:android
...
CWE    1
CWE-255
OVAL    2
oval:org.secpod.oval:def:63964
oval:org.secpod.oval:def:63946

© SecPod Technologies