Description
The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-4873 | The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities. |
References
History
No history.
Subscriptions
Fortinet
Subscribe
Fortigate-1000c
Subscribe
Fortigate-100d
Subscribe
Fortigate-110c
Subscribe
Fortigate-1240b
Subscribe
Fortigate-200b
Subscribe
Fortigate-20c
Subscribe
Fortigate-300c
Subscribe
Fortigate-3040b
Subscribe
Fortigate-310b
Subscribe
Fortigate-311b
Subscribe
Fortigate-3140b
Subscribe
Fortigate-3240c
Subscribe
Fortigate-3810a
Subscribe
Fortigate-3950b
Subscribe
Fortigate-40c
Subscribe
Fortigate-5001a-sw
Subscribe
Fortigate-5001b
Subscribe
Fortigate-5020
Subscribe
Fortigate-5060
Subscribe
Fortigate-50b
Subscribe
Fortigate-5101c
Subscribe
Fortigate-5140b
Subscribe
Fortigate-600c
Subscribe
Fortigate-60c
Subscribe
Fortigate-620b
Subscribe
Fortigate-800c
Subscribe
Fortigate-80c
Subscribe
Fortigate-voice-80c
Subscribe
Fortigaterugged-100c
Subscribe
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T20:50:18.189Z
Reserved: 2012-09-17T00:00:00.000Z
Link: CVE-2012-4948
No data.
Status : Modified
Published: 2012-11-14T12:30:59.507
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-4948
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD