CVE Vulnerabilities

CVE-2015-2323

Published: Aug 11, 2015 | Modified: Dec 03, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 5.0.9 5.0.9
Fortios Fortinet 5.0.10 5.0.10
Fortios Fortinet 5.2.1 5.2.1
Fortios Fortinet 5.0.5 5.0.5
Fortios Fortinet 5.0.1 5.0.1
Fortios Fortinet 5.0.2 5.0.2
Fortios Fortinet 5.0.7 5.0.7
Fortios Fortinet 5.0.4 5.0.4
Fortios Fortinet 5.0.11 5.0.11
Fortios Fortinet 5.0.8 5.0.8
Fortios Fortinet 5.2.3 5.2.3
Fortios Fortinet 5.2.0 5.2.0
Fortios Fortinet 5.2.2 5.2.2
Fortios Fortinet 5.0.0 5.0.0
Fortios Fortinet 5.0.3 5.0.3
Fortios Fortinet 5.0.6 5.0.6

References