CVE-2014-0351
10.09.2014, 18:55
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortios | 𝑥 ≤ 4.3.15 |
| fortinet | fortios | 4.3.10 |
| fortinet | fortios | 4.3.12 |
| fortinet | fortios | 4.3.13 |
| fortinet | fortios | 4.3.14 |
| fortinet | fortios | 5.0.0 |
| fortinet | fortios | 5.0.3 |
| fortinet | fortios | 5.0.4 |
| fortinet | fortios | 5.0.5 |
| fortinet | fortios | 5.0.6 |
| fortinet | fortios | 5.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References