CVE-2016-8495
published 2017-02-13CVE-2016-8495: An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted…
PriorityP337high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
EPSS
0.90%
55.4th percentile
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanager_firmware | — | — |
| fortinet | fortimanagerfirmware | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vq5h-hrvh-ff3m: An improper certificate validation vulnerability in Fortinet FortiManager 5
ghsa_unreviewed·2022-05-17
CVE-2016-8495 [HIGH] CWE-200 GHSA-vq5h-hrvh-ff3m: An improper certificate validation vulnerability in Fortinet FortiManager 5
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
Fortinet
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 al...
vendor_fortinet·2017-02-13·CVSS 7.4
CVE-2016-8495 [HIGH] CWE-200 An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 al...
FG-IR-16-055: An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 al...
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
CVEs: CVE-2016-8495
CWEs: CWE-200
CVSS: 7.4 (high)
Affected products: FortiManager, FortiManagerfirmware, Fortinet, Fortisandbox
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published