PT-2012-5682 · Fortinet · Fortigate Utm

Publicado

2012-11-14

·

Atualizado

2016-12-07

·

CVE-2012-4948

CVSS v2.0

5.3

Média

VetorAV:A/AC:H/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fortinet Fortigate UTM appliances (affected versions not specified)
Description The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and the same private key across different customers' installations. This makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet CA SSLProxy certificate in a list of trusted root certification authorities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4948

Produtos afetados

Fortigate Utm