CVE-2015-2323: Fortinet FortiOS
Medium severity, CVSS 6.4. EPSS: 1.5% chance of exploitation in the next 30 days.
FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to FortiGuard servers, which allows man-in-the-middle attackers to spoof TLS content by modifying packets.
Affected products
- Fortinet FortiOS: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only; version 5.0.5 only; …
Published 2015-08-11. Last modified 2026-06-17.