CVE-2015-1570
mediumCVSS v3 Base Score
4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Score
0.1%
Exploitation probability in 30 days
Top 67% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Published: February 10, 2015 (4110 days ago)
Last Modified: May 6, 2026
Vendor: Fortinet
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.
CWE
CWE-310Affected Products
fortinet forticlient