Security Advisory

CVE-2015-2323

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-08-11 14:00:00
Last updated 2024-08-06 05:10:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.