[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-4948Date: (C)2012-11-14   (M)2023-12-22


The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.3
Exploit Score: 3.2
Impact Score: 7.8
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-56382
OSVDB-87048
VU#111708

CPE    29
cpe:/h:fortinet:fortigate-110c:-
cpe:/h:fortinet:fortigate-5020:-
cpe:/h:fortinet:fortigate-5060:-
cpe:/h:fortinet:fortigate-200b:-
...
CWE    1
CWE-295

© SecPod Technologies