CVE-2015-2323
FortiOS 5.0.x < 5.0.12 and 5.2.x < 5.2.4 - Weak Cipher Suite Support in TLS Connections to FortiGuard Servers
Title source: llmDescription
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www.fortiguard.com/advisory/FG-IR-15-021/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033092
Vendor Advisory x_refsource_confirm
http://fortiguard.com/advisory/2015-07-24-weak-ciphers-suites-are-presented-towards-fortiguard-servers
Scores
EPSS
0.0029
EPSS Percentile
52.3%
Details
CWE
CWE-310
Status
published
Products (16)
fortinet/fortios
5.0.0
fortinet/fortios
5.0.1
fortinet/fortios
5.0.2
fortinet/fortios
5.0.3
fortinet/fortios
5.0.4
fortinet/fortios
5.0.5
fortinet/fortios
5.0.6
fortinet/fortios
5.0.7
fortinet/fortios
5.0.8
fortinet/fortios
5.0.9
... and 6 more
Published
Aug 11, 2015
Tracked Since
Feb 18, 2026