Description
The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack.
References (3)
Core 3
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/125
Exploit x_refsource_misc
http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiOS_Multiple_Vulnerabilities.pdf
Vendor Advisory x_refsource_misc
http://www.fortiguard.com/advisory/FG-IR-15-002/
Scores
EPSS
0.0015
EPSS Percentile
35.7%
Details
CWE
CWE-310
Status
published
Products (1)
fortinet/fortios
5.0.7
Published
Feb 10, 2015
Tracked Since
Feb 18, 2026