Some Fortinet products used hardcoded keys and weak encryption for communications
Security Affairs
NOVEMBER 26, 2019
Security researchers from SEC Consult Vulnerability Lab discovered that multiple Fortinet products use a weak encryption cipher (βXORβ with a static key) and cryptographic keys to communicate with the FortiGuard Web Filter, AntiSpam and AntiVirus cloud services. UDP ports 53, 8888 and TCP port 80 (HTTP POST /fgdsvc).
Let's personalize your content