CVE-2022-29060
published 2022-07-19CVE-2022-29060: A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may…
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.58%
43.5th percentile
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortiddos | — | — |
| fortinet | fortinet_fortiddos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2,...
vendor_fortinet·2022-07-19·CVSS 8.1
CVE-2022-29060 [HIGH] CWE-798 A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2,...
FG-IR-22-071: A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2,...
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
CVEs: CVE-2022-29060
CWEs: CWE-798
CVSS: 8.1 (high)
Affected products: FortiDDoS
GHSA
GHSA-vgx6-62w9-6xwh: A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5
ghsa_unreviewed·2022-07-20
CVE-2022-29060 [HIGH] CWE-798 GHSA-vgx6-62w9-6xwh: A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-19
Published