An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1037805 | vdb entry |
https://fortiguard.com/advisory/FG-IR-16-055 | vendor advisory |
http://www.securityfocus.com/bid/96157 | vdb entry third party advisory |