CVE-2016-8492: Fortinet FortiOS

Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.

The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption.

Affected products

  • Fortinet FortiOS: up to and including 4.3.18; version 4.3.0 only; version 4.3.10 only; version 4.3.12 only; version 4.3.13 only; version 4.3.14 only; …

Published 2017-02-08. Last modified 2026-06-17.