PT-2012-5682 · Fortinet · Fortigate Utm

Published

2012-11-14

·

Updated

2016-12-07

·

CVE-2012-4948

CVSS v2.0

5.3

Medium

VectorAV:A/AC:H/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fortinet Fortigate UTM appliances (affected versions not specified)
Description The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and the same private key across different customers' installations. This makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet CA SSLProxy certificate in a list of trusted root certification authorities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4948

Affected Products

Fortigate Utm