The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-02-10 12:59
Updated : 2015-02-11 11:35
NVD link : CVE-2015-1570
Mitre link : CVE-2015-1570
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
fortinet
- forticlient