VDB

CVE-2012-4948

CVE-2012-4948 PUBLISHED CVSS 5.300000190734863 MEDIUM

The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.

EPSS 0.17% · 38.6th percentile

Risk Scores

CVSS 2.0
5.300000190734863
EPSS Score
0.17%
38.6th percentile

Affected Products

VendorProductVersions
fortinetfortigate-60c
fortinetfortigate-300c
fortinetfortigate-80c
fortinetfortigate-40c
fortinetfortigaterugged-100c
fortinetfortigate-3040b
fortinetfortigate-600c
fortinetfortigate-100d
fortinetfortigate-1000c
fortinetfortigate-5140b
fortinetfortigate-5001a-sw
fortinetfortigate-5020
fortinetfortigate-620b
fortinetfortigate-50b
fortinetfortigate-800c
fortinetfortigate-3240c
fortinetfortigate-voice-80c
n/an/a*
fortinetfortigate-110c
fortinetfortigate-311b

…and 10 more

Timeline

  • Nov 14, 2012 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›