CVE-2015-5965
Status: ModifiedMedium (5)—
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.09%
- Percentile among all scored CVEs: 81
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-20
References
- http://www.fortiguard.com/advisory/FG-IR-15-016/
- http://www.securityfocus.com/bid/76065
- http://www.securitytracker.com/id/1033256
- https://security.gentoo.org/glsa/201508-01
- https://vivaldi.net/en-US/blogs/entry/the-poodle-has-friends
- http://www.fortiguard.com/advisory/FG-IR-15-016/
- http://www.securityfocus.com/bid/76065
- http://www.securitytracker.com/id/1033256
- https://security.gentoo.org/glsa/201508-01
- https://vivaldi.net/en-US/blogs/entry/the-poodle-has-friends
Raw JSON (NVD)
Show
{
"id": "CVE-2015-5965",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-08-11T14:59:16.477",
"references": [
{
"url": "http://www.fortiguard.com/advisory/FG-IR-15-016/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/76065",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1033256",
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201508-01",
"source": "cve@mitre.org"
},
{
"url": "https://vivaldi.net/en-US/blogs/entry/the-poodle-has-friends",
"source": "cve@mitre.org"
},
{
"url": "http://www.fortiguard.com/advisory/FG-IR-15-016/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/76065",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1033256",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201508-01",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vivaldi.net/en-US/blogs/entry/the-poodle-has-friends",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field."
},
{
"lang": "es",
"value": "Vulnerabilidad en la funciionalidad SSL-VPN en Fortinet FortiOS en versiones anteriores a 4.3.13, sólo comprueba el primer byte de la TLS MAC en los mensajes finalizados, lo que hace que sea más fácil para atacantes remotos suplantar el contenido cifrado a través de un campo MAC manipulado."
}
],
"lastModified": "2026-06-17T00:30:12.030",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4A9AD38-4005-4B33-AB47-5E81F9AB5E32",
"versionEndIncluding": "4.3.12"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}