The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2015-02-10 20:59
Updated : 2015-02-11 19:35
NVD link : CVE-2015-1570
Mitre link : CVE-2015-1570
CVE.ORG link : CVE-2015-1570
JSON object : View
Products Affected
fortinet
- forticlient
CWE
CWE-310
Cryptographic Issues