CVE-2018-9194
Last modified
CVE-2018-9194 is a vulnerability of currently unknown severity. A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 5.4.6, <= 5.4.9 |
| Fortinet | Fortios | 6.0.0 |
| Fortinet | Fortios | 6.0.1 |
References
- https://fortiguard.com/advisory/FG-IR-17-302Vendor Advisory
- https://robotattack.org/Third Party Advisory
- https://www.kb.cert.org/vuls/id/144389Third Party Advisory, US Government Resource
- https://fortiguard.com/advisory/FG-IR-17-302Vendor Advisory
- https://robotattack.org/Third Party Advisory
- https://www.kb.cert.org/vuls/id/144389Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9194?
How severe is CVE-2018-9194?
How do I fix CVE-2018-9194?
Are you affected by CVE-2018-9194?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
