The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fortinet
Subscribe
|
Fortigate-1000c
Subscribe
Fortigate-100d
Subscribe
Fortigate-110c
Subscribe
Fortigate-1240b
Subscribe
Fortigate-200b
Subscribe
Fortigate-20c
Subscribe
Fortigate-300c
Subscribe
Fortigate-3040b
Subscribe
Fortigate-310b
Subscribe
Fortigate-311b
Subscribe
Fortigate-3140b
Subscribe
Fortigate-3240c
Subscribe
Fortigate-3810a
Subscribe
Fortigate-3950b
Subscribe
Fortigate-40c
Subscribe
Fortigate-5001a-sw
Subscribe
Fortigate-5001b
Subscribe
Fortigate-5020
Subscribe
Fortigate-5060
Subscribe
Fortigate-50b
Subscribe
Fortigate-5101c
Subscribe
Fortigate-5140b
Subscribe
Fortigate-600c
Subscribe
Fortigate-60c
Subscribe
Fortigate-620b
Subscribe
Fortigate-800c
Subscribe
Fortigate-80c
Subscribe
Fortigate-voice-80c
Subscribe
Fortigaterugged-100c
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-4873 | The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T20:50:18.189Z
Reserved: 2012-09-17T00:00:00
Link: CVE-2012-4948
No data.
Status : Deferred
Published: 2012-11-14T12:30:59.507
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4948
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD