VulnerabilityModified
CVE-2018-9192
Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.
MEDIUM 5.9EPSS 1.12%
Does this matter?
Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.
Description
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- fortinet/fortios
- Source
- psirt@fortinet.com
References
- https://fortiguard.com/advisory/FG-IR-17-302Vendor Advisory
- https://robotattack.org/Third Party Advisory
- https://www.kb.cert.org/vuls/id/144389Third Party Advisory, US Government Resource
- https://fortiguard.com/advisory/FG-IR-17-302Vendor Advisory
- https://robotattack.org/Third Party Advisory
- https://www.kb.cert.org/vuls/id/144389Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.