CVE-2012-4948

Fortinet Fortigate UTM - Info Disclosure

Title source: llm
STIX 2.1

Description

The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/111708
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56382
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/87048

Scores

EPSS 0.0017
EPSS Percentile 38.4%

Details

CWE
CWE-295
Status published
Products (29)
fortinet/fortigate-1000c
fortinet/fortigate-100d
fortinet/fortigate-110c
fortinet/fortigate-1240b
fortinet/fortigate-200b
fortinet/fortigate-20c
fortinet/fortigate-300c
fortinet/fortigate-3040b
fortinet/fortigate-310b
fortinet/fortigate-311b
... and 19 more
Published Nov 14, 2012
Tracked Since Feb 18, 2026