cbcvebase.
CVE-2018-9195
published 2019-11-21

CVE-2018-9195: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on…

PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.77%
75.5th percentile
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages. Affected products include FortiClient for Windows 6.0.6 and below, FortiOS 6.0.7 and below, FortiClient for Mac OS 6.2.1 and below.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetforticlient<= 6.0.6
fortinetforticlient<= 6.2.1
fortinetforticlient
fortinetforticlient_for_mac_os
fortinetforticlient_for_windows
fortinetfortiguard
fortinetfortios<= 6.0.6
fortinetfortios
fortinetfortios

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.