The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortios | 4.3.13 | 4.3.13.x |
| fortinet / fortios | 4.3.12 | 4.3.12.x |
| fortinet / fortios | 5.0.5 | 5.0.5.x |
| fortinet / fortios | 4.3.10 | 4.3.10.x |
| fortinet / fortios | 5.0.7 | 5.0.7.x |
| fortinet / fortios | 5.0.4 | 5.0.4.x |
| fortinet / fortios | 4.3.14 | 4.3.14.x |
| fortinet / fortios | - | 4.3.15.x |
| fortinet / fortios | 5.0.0 | 5.0.0.x |
| fortinet / fortios | 5.0.3 | 5.0.3.x |
| fortinet / fortios | 5.0.6 | 5.0.6.x |