CVE-2019-15703: High severity fortios vulnerability
An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS client with a RSA handshake and mutual ECDSA authentication via the help of flush+reload side channel attacks in FortiGate VM models only.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15703?
CVE-2019-15703 has been classified as a high-severity vulnerability due to its potential to allow attackers to recover ECDSA secrets.
How do I fix CVE-2019-15703?
To mitigate CVE-2019-15703, upgrade FortiOS to version 6.2.3 or later, or enable hardware TRNG support.
What types of devices are affected by CVE-2019-15703?
CVE-2019-15703 affects Fortinet FortiOS devices that do not enable hardware TRNG and include versions up to 6.2.3.
What impact does CVE-2019-15703 have on TLS connections?
CVE-2019-15703 can allow attackers to theoretically recover the long-term ECDSA secret during RSA handshake in TLS connections.
Is CVE-2019-15703 related to a software or hardware issue?
CVE-2019-15703 is primarily a software issue related to insufficient entropy in the pseudorandom number generator (PRNG) in FortiOS.