Vulnerability Description
An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to theoretically recover the long term ECDSA secret in a TLS client with a RSA handshake and mutual ECDSA authentication via the help of flush+reload side channel attacks in FortiGate VM models only.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | <= 5.6.9 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-19-186Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-19-186Vendor Advisory
FAQ
What is CVE-2019-15703?
CVE-2019-15703 is a vulnerability with a CVSS score of 7.5 (HIGH). An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable hardware TRNG token and models not support builtin TRNG seed allows attacker to th...
How severe is CVE-2019-15703?
CVE-2019-15703 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15703?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortios.