CVE Vulnerabilities

CVE-2015-1570

Published: Feb 10, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected Software

NameVendorStart VersionEnd Version
ForticlientFortinet5.2.3.091 (including)5.2.3.091 (including)
ForticlientFortinet5.2.028 (including)5.2.028 (including)

References