CVE-2015-2323

FortiOS 5.0.x < 5.0.12 and 5.2.x < 5.2.4 - Weak Cipher Suite Support in TLS Connections to FortiGuard Servers

Title source: llm
STIX 2.1

Description

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www.fortiguard.com/advisory/FG-IR-15-021/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033092

Scores

EPSS 0.0029
EPSS Percentile 52.3%

Details

CWE
CWE-310
Status published
Products (16)
fortinet/fortios 5.0.0
fortinet/fortios 5.0.1
fortinet/fortios 5.0.2
fortinet/fortios 5.0.3
fortinet/fortios 5.0.4
fortinet/fortios 5.0.5
fortinet/fortios 5.0.6
fortinet/fortios 5.0.7
fortinet/fortios 5.0.8
fortinet/fortios 5.0.9
... and 6 more
Published Aug 11, 2015
Tracked Since Feb 18, 2026