cbcvebase.
CVE-2022-30307
published 2022-11-02

CVE-2022-30307: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an…

PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.44%
35.7th percentile
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

Affected

5 ranges
VendorProductVersion rangeFixed in
fortinetfortinet_fortios
fortinetfortios
fortinetfortios>= 6.4.0 < 6.4.106.4.10
fortinetfortios>= 7.0.1 < 7.0.87.0.8
fortinetfortios>= 7.2.0 < 7.2.27.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.