The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortios | Fortinet | 4.3.13 | 4.3.13 |
Fortios | Fortinet | 4.3.12 | 4.3.12 |
Fortios | Fortinet | 5.0.5 | 5.0.5 |
Fortios | Fortinet | 4.3.10 | 4.3.10 |
Fortios | Fortinet | 5.0.7 | 5.0.7 |
Fortios | Fortinet | 5.0.4 | 5.0.4 |
Fortios | Fortinet | 4.3.14 | 4.3.14 |
Fortios | Fortinet | * | 4.3.15 |
Fortios | Fortinet | 5.0.0 | 5.0.0 |
Fortios | Fortinet | 5.0.3 | 5.0.3 |
Fortios | Fortinet | 5.0.6 | 5.0.6 |