CVE-2015-2323Fortinet Fortios vulnerability

CWE-3103 documents3 sources
Severity
6.4MEDIUMNVD
EPSS
0.3%
top 47.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 11
Latest updateMay 17

Description

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

NVDfortinet/fortios16 versions+15

🔴Vulnerability Details

2
GHSA
GHSA-828v-j88x-385j: FortiOS 52022-05-17
CVEList
CVE-2015-2323: FortiOS 52015-08-11
CVE-2015-2323 — Fortinet Fortios vulnerability | cvebase