CVE-2015-1570: Medium severity fortinet forticlient vulnerability
The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1570?
CVE-2015-1570 has a medium severity rating due to its potential for man-in-the-middle attacks.
How does CVE-2015-1570 affect users?
CVE-2015-1570 allows attackers to spoof servers by exploiting the lack of certificate validation in Fortinet FortiClient.
What versions are affected by CVE-2015-1570?
CVE-2015-1570 affects FortiClient version 5.2.3.091 for Android and 5.2.028 for iOS.
How do I fix CVE-2015-1570?
To mitigate CVE-2015-1570, update FortiClient to the latest version that includes fixes for certificate validation.
Is CVE-2015-1570 still a risk today?
CVE-2015-1570 remains a risk for users who have not updated their FortiClient software to address this vulnerability.