{"api_version":"1","generated_at":"2026-07-23T05:02:10+00:00","cve":"CVE-2018-9194","urls":{"html":"https://cve.report/CVE-2018-9194","api":"https://cve.report/api/cve/CVE-2018-9194.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-9194","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-9194"},"summary":{"title":"CVE-2018-9194","description":"A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2018-09-05 13:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-203"],"metrics":[],"references":[{"url":"https://fortiguard.com/advisory/FG-IR-17-302","name":"https://fortiguard.com/advisory/FG-IR-17-302","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"The ROBOT Attack - Return of Bleichenbacher's Oracle Threat | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://robotattack.org/","name":"https://robotattack.org/","refsource":"MISC","tags":["Third Party Advisory"],"title":"The ROBOT Attack - Return of Bleichenbacher's Oracle Threat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.kb.cert.org/vuls/id/144389","name":"VU#144389","refsource":"CERT-VN","tags":["Third Party Advisory","US Government Resource"],"title":"VU#144389 - TLS implementations may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-9194","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-9194","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"9194","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"6.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9194","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"6.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9194","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"6.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9194","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"6.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9194","vulnerable":"1","versionEndIncluding":"5.4.9","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@fortinet.com","DATE_PUBLIC":"2018-08-27T00:00:00","ID":"CVE-2018-9194","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"FortiOS","version":{"version_data":[{"version_value":"6.0.1, 6.0.0"},{"version_value":"5.4.9, 5.4.8, 5.4.7, 5.4.6"}]}}]},"vendor_name":"Fortinet, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information disclosure"}]}]},"references":{"reference_data":[{"name":"https://robotattack.org/","refsource":"MISC","url":"https://robotattack.org/"},{"name":"https://fortiguard.com/advisory/FG-IR-17-302","refsource":"CONFIRM","url":"https://fortiguard.com/advisory/FG-IR-17-302"},{"name":"VU#144389","refsource":"CERT-VN","url":"https://www.kb.cert.org/vuls/id/144389"}]}},"nvd":{"publishedDate":"2018-09-05 13:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-203"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:6.0.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:6.0.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.6","versionEndIncluding":"5.4.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"9194","Ordinal":"125588","Title":"CVE-2018-9194","CVE":"CVE-2018-9194","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"9194","Ordinal":"1","NoteData":"A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"9194","Ordinal":"2","NoteData":"2018-09-05","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"9194","Ordinal":"3","NoteData":"2018-09-05","Type":"Other","Title":"Modified"}]}}}