CVE-2015-1453Fortinet Forticlient vulnerability

CWE-3103 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.2%
top 63.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 2
Latest updateMay 17

Description

The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibly other sensitive data by leveraging the key to decrypt data in the Shared Preferences.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDfortinet/forticlient5.2.3.091

🔴Vulnerability Details

2
GHSA
GHSA-6gr6-h6rg-w74p: The qm class in Fortinet FortiClient 52022-05-17
CVEList
CVE-2015-1453: The qm class in Fortinet FortiClient 52015-02-02
CVE-2015-1453 — Fortinet Forticlient vulnerability | cvebase