CVE-2014-0351: Medium severity fortios vulnerability
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0351?
CVE-2014-0351 is considered to have a medium severity level as it allows for man-in-the-middle attacks.
How do I fix CVE-2014-0351?
To fix CVE-2014-0351, update your FortiOS to version 4.3.16 or later, or 5.0.8 or later.
Which FortiOS versions are affected by CVE-2014-0351?
CVE-2014-0351 affects FortiOS versions prior to 4.3.16 and 5.x versions prior to 5.0.8.
What types of attacks can exploit CVE-2014-0351?
CVE-2014-0351 can be exploited by man-in-the-middle attackers who use anonymous ciphersuites.
How can I determine if my FortiGate device is vulnerable to CVE-2014-0351?
You can determine vulnerability by checking the FortiOS version running on your FortiGate device and comparing it against the affected versions.