Blog | G5 Cyber Security

DUHK Vulnerability Offers a Quick Way to Launch a Crypto Attack

Researchers reverse engineered a set of firmware running on Fortinet devices in less than five minutes. The vulnerability stems from a problem with the ANSI X9.31 Random Number Generation algorithm. The hardcoded seed key, used at device setup or when launching algorithm, is essentially making such devices susceptible to the crypto attack. The attack could affect more than 23,000 FortiGate 4x devices using older versions of FortiOS, the researchers said. The easiest way to know if your organization is safe is to determine if your firewall or VPN achieved FIPS certification after January 2016.”]

Source: https://securityintelligence.com/news/duhk-vulnerability-offers-a-quick-way-to-launch-a-crypto-attack/

Exit mobile version