CVE-2018-9192

A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.
References
Link Resource
https://fortiguard.com/advisory/FG-IR-17-302 Vendor Advisory
https://robotattack.org/ Third Party Advisory
https://www.kb.cert.org/vuls/id/144389 Third Party Advisory US Government Resource
https://fortiguard.com/advisory/FG-IR-17-302 Vendor Advisory
https://robotattack.org/ Third Party Advisory
https://www.kb.cert.org/vuls/id/144389 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:6.0.0:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:6.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 04:15

Type Values Removed Values Added
References () https://fortiguard.com/advisory/FG-IR-17-302 - Vendor Advisory () https://fortiguard.com/advisory/FG-IR-17-302 - Vendor Advisory
References () https://robotattack.org/ - Third Party Advisory () https://robotattack.org/ - Third Party Advisory
References () https://www.kb.cert.org/vuls/id/144389 - Third Party Advisory, US Government Resource () https://www.kb.cert.org/vuls/id/144389 - Third Party Advisory, US Government Resource

Information

Published : 2018-09-05 13:29

Updated : 2024-11-21 04:15


NVD link : CVE-2018-9192

Mitre link : CVE-2018-9192

CVE.ORG link : CVE-2018-9192


JSON object : View

Products Affected

fortinet

  • fortios
CWE
CWE-203

Observable Discrepancy