CVE-2013-4669
published 2013-06-25CVE-2013-4669: FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient…
PriorityP422medium5.4CVSS 2.0
AVNACHAuNCCINAN
EPSS
0.87%
54.5th percentile
FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with an SSL session after determining that the server's X.509 certificate is invalid, which allows man-in-the-middle attackers to obtain sensitive information by leveraging a password transmission that occurs before the user warning about the certificate problem.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | <= 4.3.3.445 | — |
| fortinet | forticlient | <= 4.0.2 | — |
| fortinet | forticlient_lite | <= 4.3.3.445 | — |
| fortinet | forticlient_lite | <= 2.0 | — |
| fortinet | forticlient_ssl_vpn | <= 4.0.2012 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.htmlhttp://objectif-securite.ch/forticlient_bulletin.phphttp://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/http://www.securityfocus.com/bid/59604http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.htmlhttp://objectif-securite.ch/forticlient_bulletin.phphttp://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/http://www.securityfocus.com/bid/59604
2013-06-25
Published