CVE-2015-5965: Fortinet FortiOS

Medium severity, CVSS 5.0. EPSS: 2.1% chance of exploitation in the next 30 days.

The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.

Affected products

  • Fortinet FortiOS: up to and including 4.3.12

Published 2015-08-11. Last modified 2026-06-17.