cbcvebase.
CVE-2013-4669
published 2013-06-25

CVE-2013-4669: FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient…

PriorityP422medium5.4CVSS 2.0
AVNACHAuNCCINAN
EPSS
0.87%
54.5th percentile
FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with an SSL session after determining that the server's X.509 certificate is invalid, which allows man-in-the-middle attackers to obtain sensitive information by leveraging a password transmission that occurs before the user warning about the certificate problem.

Affected

5 ranges
VendorProductVersion rangeFixed in
fortinetforticlient<= 4.3.3.445
fortinetforticlient<= 4.0.2
fortinetforticlient_lite<= 4.3.3.445
fortinetforticlient_lite<= 2.0
fortinetforticlient_ssl_vpn<= 4.0.2012
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.