FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortios | 5.0.9 | 5.0.9.x |
| fortinet / fortios | 5.0.10 | 5.0.10.x |
| fortinet / fortios | 5.2.1 | 5.2.1.x |
| fortinet / fortios | 5.0.5 | 5.0.5.x |
| fortinet / fortios | 5.0.1 | 5.0.1.x |
| fortinet / fortios | 5.0.2 | 5.0.2.x |
| fortinet / fortios | 5.0.7 | 5.0.7.x |
| fortinet / fortios | 5.0.4 | 5.0.4.x |
| fortinet / fortios | 5.0.11 | 5.0.11.x |
| fortinet / fortios | 5.0.8 | 5.0.8.x |
| fortinet / fortios | 5.2.3 | 5.2.3.x |
| fortinet / fortios | 5.2.0 | 5.2.0.x |
| fortinet / fortios | 5.2.2 | 5.2.2.x |
| fortinet / fortios | 5.0.0 | 5.0.0.x |
| fortinet / fortios | 5.0.3 | 5.0.3.x |
| fortinet / fortios | 5.0.6 | 5.0.6.x |