CVE-2018-9194
Summary
| CVE | CVE-2018-9194 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-05 13:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used. |
Risk And Classification
Problem Types: CWE-203
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortios | 6.0.0 | All | All | All |
| Operating System | Fortinet | Fortios | 6.0.1 | All | All | All |
| Operating System | Fortinet | Fortios | 6.0.0 | All | All | All |
| Operating System | Fortinet | Fortios | 6.0.1 | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| The ROBOT Attack - Return of Bleichenbacher's Oracle Threat | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| The ROBOT Attack - Return of Bleichenbacher's Oracle Threat | MISC | robotattack.org | Third Party Advisory |
| VU#144389 - TLS implementations may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.