CVE-2018-9195
published 2019-11-21CVE-2018-9195: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.77%
75.5th percentile
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages. Affected products include FortiClient for Windows 6.0.6 and below, FortiOS 6.0.7 and below, FortiClient for Mac OS 6.2.1 and below.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | <= 6.0.6 | — |
| fortinet | forticlient | <= 6.2.1 | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient_for_mac_os | — | — |
| fortinet | forticlient_for_windows | — | — |
| fortinet | fortiguard | — | — |
| fortinet | fortios | <= 6.0.6 | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-grw5-hmpf-442m: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eave
ghsa_unreviewed·2022-05-24
CVE-2018-9195 [MEDIUM] CWE-798 GHSA-grw5-hmpf-442m: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eave
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages.
Fortinet
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit...
vendor_fortinet·2019-11-21·CVSS 5.9
CVE-2018-9195 [MEDIUM] CWE-798 Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit...
FG-IR-18-100: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit...
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages. Affected products include FortiClient for Windows 6.0.6 and below, FortiOS 6.0.7 and below, FortiClient for Mac OS 6.2.1 and below.
CVEs: CVE-2018-9195
CWEs: CWE-798
CVSS: 5.9 (medium)
Affected products: FortiClient, FortiGuard, FortiOS, Fortiguard
No detection rules found.
No public exploits indexed.
2019-11-21
Published