The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortios | Fortinet | * | 4.3.15 (including) |
Fortios | Fortinet | 4.3.10 (including) | 4.3.10 (including) |
Fortios | Fortinet | 4.3.12 (including) | 4.3.12 (including) |
Fortios | Fortinet | 4.3.13 (including) | 4.3.13 (including) |
Fortios | Fortinet | 4.3.14 (including) | 4.3.14 (including) |
Fortios | Fortinet | 5.0.0 (including) | 5.0.0 (including) |
Fortios | Fortinet | 5.0.3 (including) | 5.0.3 (including) |
Fortios | Fortinet | 5.0.4 (including) | 5.0.4 (including) |
Fortios | Fortinet | 5.0.5 (including) | 5.0.5 (including) |
Fortios | Fortinet | 5.0.6 (including) | 5.0.6 (including) |
Fortios | Fortinet | 5.0.7 (including) | 5.0.7 (including) |