CVE-2013-4669
Description
FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with an SSL session after determining that the server's X.509 certificate is invalid, which allows man-in-the-middle attackers to obtain sensitive information by leveraging a password transmission that occurs before the user warning about the certificate problem.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | not-affected | | |
| linux-kernel | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| fortinet | forticlient | {"endIncluding":"4.3.3.445"} | |
| fortinet | forticlient_lite | {"endIncluding":"4.3.3.445"} | |
| fortinet | forticlient_ssl_vpn | {"endIncluding":"4.0.2012"} | |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.html
- http://objectif-securite.ch/forticlient_bulletin.php
- http://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/
- http://www.securityfocus.com/bid/59604
- http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.html
- http://objectif-securite.ch/forticlient_bulletin.php
- http://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/
- http://www.securityfocus.com/bid/59604
CWEs
CWE-255 CWE-310
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.