CVE-2015-1453
Last modified
CVE-2015-1453 is a vulnerability of currently unknown severity. The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibly other sensitive data by leveraging the key to decrypt data in the Shared Preferences.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibly other sensitive data by leveraging the key to decrypt data in the Shared Preferences.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Forticlient | <= 5.2.3.091 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1453?
How severe is CVE-2015-1453?
How do I fix CVE-2015-1453?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1445HTTP header injection in the httpd package in fli4l before 3…
- CVE-2015-1448The integrated management service on Siemens Ruggedcom WIN51…
- CVE-2015-1449Buffer overflow in the integrated web server on Siemens Rugg…
- CVE-2015-1450SQL injection vulnerability in Restaurant Biller allows remo…
- CVE-2015-1451Multiple cross-site scripting (XSS) vulnerabilities in Forti…
- CVE-2015-1452The Control and Provisioning of Wireless Access Points (CAPW…
- CVE-2015-1454Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.…
- CVE-2015-1455Fortinet FortiAuthenticator 3.0.0 has a password of (1) slon…
- CVE-2015-1456Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL userna…
- CVE-2015-1457Fortinet FortiAuthenticator 3.0.0 allows local users to read…
- CVE-2015-1458Fortinet FortiAuthenticator 3.0.0 allows local users to bypa…
- CVE-2015-1459Cross-site scripting (XSS) vulnerability in Fortinet FortiAu…
Are you affected by CVE-2015-1453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
