Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-4948


The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.


Published

2012-11-14T12:30:59.507

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.3 (MEDIUM)

CVSSv2 Vector

AV:A/AC:H/Au:N/C:C/I:P/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.2

Impact Score

7.8

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware fortinet fortigate-1000c - Yes
Hardware fortinet fortigate-100d - Yes
Hardware fortinet fortigate-110c - Yes
Hardware fortinet fortigate-1240b - Yes
Hardware fortinet fortigate-200b - Yes
Hardware fortinet fortigate-20c - Yes
Hardware fortinet fortigate-300c - Yes
Hardware fortinet fortigate-3040b - Yes
Hardware fortinet fortigate-310b - Yes
Hardware fortinet fortigate-311b - Yes
Hardware fortinet fortigate-3140b - Yes
Hardware fortinet fortigate-3240c - Yes
Hardware fortinet fortigate-3810a - Yes
Hardware fortinet fortigate-3950b - Yes
Hardware fortinet fortigate-40c - Yes
Hardware fortinet fortigate-5001a-sw - Yes
Hardware fortinet fortigate-5001b - Yes
Hardware fortinet fortigate-5020 - Yes
Hardware fortinet fortigate-5060 - Yes
Hardware fortinet fortigate-50b - Yes
Hardware fortinet fortigate-5101c - Yes
Hardware fortinet fortigate-5140b - Yes
Hardware fortinet fortigate-600c - Yes
Hardware fortinet fortigate-60c - Yes
Hardware fortinet fortigate-620b - Yes
Hardware fortinet fortigate-800c - Yes
Hardware fortinet fortigate-80c - Yes
Hardware fortinet fortigate-voice-80c - Yes
Hardware fortinet fortigaterugged-100c - Yes

References