AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-1571

MEDIUM · CVSS 4.3 EPSS 0.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-02-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. It affects Fortinet, FortiOS.

CVE
CVE-2015-1571
Severity
MEDIUM
CVSS
4.3
EPSS
0.86%
Fortinet FortiOS

Original NVD Description

The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack.