← Back

CVE-2018-9192

nvd nist
Published: Sep 5, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.

Affected (3)

Products: Fortinet: Fortios
1 product
Fortios
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 5.4.6 to 5.4.9
Version 6.0.0
Version 6.0.1

References (6)

Source: psirt@fortinet.com
Vendor Advisory
Source: psirt@fortinet.com
Third Party Advisory
Source: psirt@fortinet.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.