Описание
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
Ссылки
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Одно из
EPSS
5.4 Medium
CVSS2
Дефекты
Связанные уязвимости
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
Уязвимость службы FortiManager операционной системы FortiOS, позволяющая нарушителю осуществить атаку типа «человек посередине», получить доступ к защищаемой информации и перенаправить сетевой трафик
EPSS
5.4 Medium
CVSS2