CVE-2013-4669
Severity CVSS v4.0:
Pending analysis
Type:
CWE-255
Credentials Management
Publication date:
25/06/2013
Last modified:
11/04/2025
Description
FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and FortiClient SSL VPN before 4.0.2258 on Linux proceed with an SSL session after determining that the server's X.509 certificate is invalid, which allows man-in-the-middle attackers to obtain sensitive information by leveraging a password transmission that occurs before the user warning about the certificate problem.
Impact
Base Score 2.0
5.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:*:*:* | 4.3.3.445 (including) | |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:forticlient_lite:*:*:*:*:*:*:*:* | 4.3.3.445 (including) | |
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:forticlient_ssl_vpn:*:*:*:*:*:*:*:* | 4.0.2012 (including) | |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:*:*:* | 4.0.2 (including) | |
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:fortinet:forticlient_lite:*:*:*:*:*:*:*:* | 2.0 (including) | |
cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.html
- http://objectif-securite.ch/forticlient_bulletin.php
- http://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/
- http://www.securityfocus.com/bid/59604
- http://archives.neohapsis.com/archives/fulldisclosure/2013-05/0001.html
- http://objectif-securite.ch/forticlient_bulletin.php
- http://www.fortiguard.com/advisory/Potential-Man-In-The-Middle-Vulnerability-in-FortiClient-VPN/
- http://www.securityfocus.com/bid/59604