CVE-2018-9195: Medium severity fortinet forticlient ssl vpn vulnerability
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages. Affected products include FortiClient for Windows 6.0.6 and below, FortiOS 6.0.7 and below, FortiClient for Mac OS 6.2.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-9195?
CVE-2018-9195 is a vulnerability involving the use of a hardcoded cryptographic key in the FortiGuard services communication protocol, allowing a Man-in-the-Middle attack.
How can a Man-in-the-Middle attack exploit CVE-2018-9195?
A Man-in-the-Middle attacker with knowledge of the hardcoded key can eavesdrop on and modify information sent and received through the affected FortiGuard services.
Which software versions are affected by CVE-2018-9195?
FortiClient for Windows versions up to and including 6.0.6, FortiClient for macOS versions up to and including 6.2.1, and FortiOS versions up to and including 6.0.6 are affected.
What is the severity of CVE-2018-9195?
The severity of CVE-2018-9195 is medium, with a CVSS severity score of 5.9.
Where can I find more information about CVE-2018-9195?
More information about CVE-2018-9195 can be found at the following URL: https://fortiguard.com/advisory/FG-IR-18-100