vulnerability

Fortinet FortiManager: CVE-2016-8495: FortiManager TLS certificate validation failure

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Feb 13, 2017
Added
May 15, 2017
Modified
Oct 30, 2017

Description

An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.

Solutions

fortimanager-cve-2016-8495-1fortimanager-cve-2016-8495-2
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.