CVE-2012-4948
5.3
Vector
AV:A/AC:H/Au:N/C:C/I:P/A:N
Exploitability: 3.2 / Impact: 7.8
Source: NVD
Description
The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.
Affected (29)
Products: Fortinet: Fortigate 1000c, Fortigate 100d, Fortigate 110c, Fortigate 1240b, Fortigate 200b, Fortigate 20c, Fortigate 300c, Fortigate 3040b, Fortigate 310b, Fortigate 311b, Fortigate 3140b, Fortigate 3240c, Fortigate 3810a, Fortigate 3950b, Fortigate 40c, Fortigate 5001a Sw, Fortigate 5001b, Fortigate 5020, Fortigate 5060, Fortigate 50b, Fortigate 5101c, Fortigate 5140b, Fortigate 600c, Fortigate 60c, Fortigate 620b, Fortigate 800c, Fortigate 80c, Fortigate Voice 80c, Fortigaterugged 100c
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
References (6)
Source: cret@cert.org
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.