CVE-2018-9194

MEDIUM

FortiOS 5.4.6-5.4.9, 6.0.0-6.0.1 - Plaintext Recovery and Man-in-the-Middle Attack via RSA PKCS #1 v1.5 Encryption

Title source: llm
STIX 2.1

Description

A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://robotattack.org/
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-17-302
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/144389

Scores

CVSS v3 5.9
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (3)
fortinet/fortios 6.0.0
fortinet/fortios 6.0.1
fortinet/fortios 5.4.6 - 5.4.9
Published Sep 05, 2018
Tracked Since Feb 18, 2026