← Back

CVE-2012-4948

nvd nist
Published: Nov 14, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.3
Vector
AV:A/AC:H/Au:N/C:C/I:P/A:N
Exploitability: 3.2 / Impact: 7.8
Source: NVD

Description

The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.

Affected (29)

29 products
Fortigate 1000c
Fortigate 100d
Fortigate 110c
Fortigate 1240b
Fortigate 200b
Fortigate 20c
Fortigate 300c
Fortigate 3040b
Fortigate 310b
Fortigate 311b
Fortigate 3140b
Fortigate 3240c
Fortigate 3810a
Fortigate 3950b
Fortigate 40c
Fortigate 5001a Sw
Fortigate 5001b
Fortigate 5020
Fortigate 5060
Fortigate 50b
Fortigate 5101c
Fortigate 5140b
Fortigate 600c
Fortigate 60c
Fortigate 620b
Fortigate 800c
Fortigate 80c
Fortigate Voice 80c
Fortigaterugged 100c
Configuration A
29 vulnerable

References (6)

Source: cret@cert.org
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.