CVE-2018-9194: Medium severity fortios vulnerability
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9194?
CVE-2018-9194 is classified as a high severity vulnerability due to its potential for plaintext recovery of encrypted messages.
How do I fix CVE-2018-9194?
To mitigate CVE-2018-9194, upgrade Fortinet FortiOS to versions 5.4.10 or later, or 6.0.2 or later.
What type of attack does CVE-2018-9194 enable?
CVE-2018-9194 allows for plaintext recovery of encrypted messages and Man-in-the-middle (MiTM) attacks.
Which versions of Fortinet FortiOS are affected by CVE-2018-9194?
Fortinet FortiOS versions 5.4.6 to 5.4.9 and versions 6.0.0 and 6.0.1 are affected by CVE-2018-9194.
Is a server's private key needed to exploit CVE-2018-9194?
No, CVE-2018-9194 can potentially be exploited without knowledge of the server's private key.