AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-9195

MEDIUM · CVSS 5.9 EPSS 1.57%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-11-21 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. It affects FortiOS, Windows.

CVE
CVE-2018-9195
Severity
MEDIUM
CVSS
5.9
EPSS
1.57%
FortiOS Windows

Original NVD Description

Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messages. Affected products include FortiClient for Windows 6.0.6 and below, FortiOS 6.0.7 and below, FortiClient for Mac OS 6.2.1 and below.

Related CVEs

Other vulnerabilities affecting the same vendor(s)