The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
References
Configurations
Information
Published : 2015-08-11 07:59
Updated : 2016-12-23 18:59
NVD link : CVE-2015-5965
Mitre link : CVE-2015-5965
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
fortinet
- fortios